CVE-2021-39151: XStream is vulnerable to an Arbitrary Code Execution attack
A flaw was found in xstream, a simple library used to serialize objects to XML and back again. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 0:1.3.1-16.el7_9 - Upgrade
Upgrade
debian/libxstream-javato a version that resolves this vulnerability.Fixed in 1.4.11.1-1+deb10u3Fixed in 1.4.11.1-1+deb10u4Fixed in 1.4.15-3+deb11u2Fixed in 1.4.20-1 - Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Upgrade
Upgrade
xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Configuration
Configure XStream's security framework to use a whitelist limited to the minimal required types.
XStream security framework whitelist = limited to the minimal required types
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-39151?
CVE-2021-39151 is a vulnerability in the XStream library that allows a remote attacker to execute arbitrary code by manipulating the input stream.
How severe is CVE-2021-39151?
CVE-2021-39151 has a severity rating of 8.5 (high).
Which software versions are affected by CVE-2021-39151?
Versions up to and excluding 1.4.18 of xstream, versions up to and excluding 1.3.1-16.el7_9 of xstream (from Red Hat), and various versions of libxstream-java, Fedora, and Debian are affected by CVE-2021-39151.
How can I fix CVE-2021-39151?
To fix CVE-2021-39151, update the xstream library to version 1.4.18 or apply the recommended patches for the affected software versions.
Where can I find more information about CVE-2021-39151?
More information about CVE-2021-39151 can be found in the GitHub Advisory, XStream CVE-2021-39151 page, and the Red Hat Bugzilla page.