CVE-2021-39148: XStream is vulnerable to an Arbitrary Code Execution attack
A flaw was found in xstream, a simple library used to serialize objects to XML and back again. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 0:1.3.1-16.el7_9 - Upgrade
Upgrade
debian/libxstream-javato a version that resolves this vulnerability.Fixed in 1.4.11.1-1+deb10u3Fixed in 1.4.11.1-1+deb10u4Fixed in 1.4.15-3+deb11u2Fixed in 1.4.20-1 - Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Upgrade
Upgrade
xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Configuration
Set up XStream's security framework using a whitelist limited to the minimal required types (per the advisory recommendation) to prevent remote arbitrary code execution when processing untrusted XML.
XStream security framework whitelist = whitelist limited to the minimal required types
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-39148?
CVE-2021-39148 is a vulnerability in the xstream library that allows a remote attacker to execute arbitrary code by manipulating the input stream.
What is the severity of CVE-2021-39148?
The severity of CVE-2021-39148 is high, with a CVSS score of 8.5.
Which software versions are affected by CVE-2021-39148?
The affected software versions include xstream 1.4.18, xstream 0:1.3.1-16.el7_9, and other specific versions listed in the vulnerability description.
How can I fix CVE-2021-39148?
To fix CVE-2021-39148, it is recommended to upgrade to xstream version 1.4.18 or apply the specified patches provided by the software vendors.
Where can I find more information about CVE-2021-39148?
You can find more information about CVE-2021-39148 in the references provided: [GitHub Advisory](https://github.com/x-stream/xstream/security/advisories/GHSA-qrx8-8545-4wg2), [CVE-2021-39148 Information](https://x-stream.github.io/CVE-2021-39148.html), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1997782).