原始 OSV JSON{
"id": "GHSA-59jw-jqf4-3wq3",
"aliases": [
"CVE-2021-21344"
],
"details": "### Impact\nThe vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types.\n\n### Patches\nIf you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.16.\n\n### Workarounds\nSee [workarounds](https://x-stream.github.io/security.html#workaround) for the different versions covering all CVEs.\n\n### References\nSee full information about the nature of the vulnerability and the steps to reproduce it in XStream's documentation for [CVE-2021-21344](https://x-stream.github.io/CVE-2021-21344.html).\n\n### Credits\n钟潦贵 (Liaogui Zhong) found and reported the issue to XStream and provided the required information to reproduce it.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [XStream](https://github.com/x-stream/xstream/issues)\n* Contact us at [XStream Google Group](https://groups.google.com/group/xstream-user)",
"summary": "XStream is vulnerable to an Arbitrary Code Execution attack",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4.16"
}
]
}
],
"package": {
"name": "com.thoughtworks.xstream:xstream",
"ecosystem": "Maven"
}
}
],
"modified": "2022-02-08T21:33:08Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"
}
],
"published": "2021-03-22T23:28:23Z",
"references": [
{
"url": "https://github.com/x-stream/xstream/security/advisories/GHSA-59jw-jqf4-3wq3",
"type": "WEB"
},
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21344",
"type": "ADVISORY"
},
{
"url": "https://github.com/x-stream/xstream",
"type": "PACKAGE"
},
{
"url": "https://lists.apache.org/thread.html/r8244fd0831db894d5e89911ded9c72196d395a90ae655414d23ed0dd@%3Cusers.activemq.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.apache.org/thread.html/r9ac71b047767205aa22e3a08cb33f3e0586de6b2fac48b425c6e16b0@%3Cdev.jmeter.apache.org%3E",
"type": "WEB"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00002.html",
"type": "WEB"
},
{
"url": "https://lists.fedoraproject.org/archives/list/[email protected] /message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP",
"type": "WEB"
},
{
"url": "https://lists.fedoraproject.org/archives/list/[email protected] /message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7",
"type": "WEB"
},
{
"url": "https://lists.fedoraproject.org/archives/list/[email protected] /message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB",
"type": "WEB"
},
{
"url": "https://security.netapp.com/advisory/ntap-20210430-0002",
"type": "WEB"
},
{
"url": "https://www.debian.org/security/2021/dsa-5004",
"type": "WEB"
},
{
"url": "https://www.oracle.com//security-alerts/cpujul2021.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpujan2022.html",
"type": "WEB"
},
{
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
"type": "WEB"
},
{
"url": "https://x-stream.github.io/CVE-2021-21344.html",
"type": "WEB"
},
{
"url": "https://x-stream.github.io/security.html#workaround",
"type": "WEB"
},
{
"url": "http://x-stream.github.io/changes.html#1.4.16",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-434",
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2021-03-23T00:15:00Z",
"github_reviewed_at": "2021-03-22T23:23:49Z"
}
}