CVE-2021-39153: XStream is vulnerable to an Arbitrary Code Execution attack
A flaw was found in xstream, a simple library used to serialize objects to XML and back again. This flaw allows a remote attacker to load and execute arbitrary code from a remote host by manipulating the processed input stream. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Other sources
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 0:1.3.1-16.el7_9 - Upgrade
Upgrade
debian/libxstream-javato a version that resolves this vulnerability.Fixed in 1.4.11.1-1+deb10u3Fixed in 1.4.11.1-1+deb10u4Fixed in 1.4.15-3+deb11u2Fixed in 1.4.20-1 - Upgrade
Upgrade
redhat/xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Upgrade
Upgrade
xstreamto a version that resolves this vulnerability.Fixed in 1.4.18 - Configuration
Ensure XStream's security framework is configured with a whitelist limited to the minimal required types (as recommended in the advisory) to prevent arbitrary code execution when processing manipulated input streams.
XStream XStream security framework whitelist (allowed types) = whitelist limited to the minimal required types
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-39153?
CVE-2021-39153 is a vulnerability found in the xstream library, which allows a remote attacker to execute arbitrary code by manipulating the processed input stream.
What is the severity of CVE-2021-39153?
The severity of CVE-2021-39153 is high, with a severity value of 8.5.
How does CVE-2021-39153 affect xstream?
CVE-2021-39153 affects xstream by allowing a remote attacker to load and execute arbitrary code from a remote host through the manipulated input stream.
Which versions of xstream are affected by CVE-2021-39153?
Versions up to and excluding 1.4.18 are affected by CVE-2021-39153.
How can CVE-2021-39153 be fixed?
To fix CVE-2021-39153, update xstream to version 1.4.18 or apply the recommended remedy provided by Red Hat.