XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xstreamUpgrade xstream-javadoc | Aug 6, 2021 | May 28, 2021 |
| Centos_linux | — | Upgrade xstream-javadocUpgrade xstream | Jul 13, 2021 | May 28, 2021 |
| Debian | — | Upgrade libxstream-java | Jul 8, 2021 | May 28, 2021 |
| Oracle_linux | — | Upgrade xstream-javadocUpgrade xstream | Jul 13, 2021 | May 14, 2021 |
| Redhat_linux | — | Upgrade xstreamUpgrade xstream-javadoc | Jul 13, 2021 | May 28, 2021 |
| Suse | — | Upgrade xstream-benchmarkUpgrade xstreamUpgrade xstream-javadocUpgrade xstream-parent | Jun 18, 2021 | May 28, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | May 28, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub