Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-43859

Опубликовано: 29 янв. 2022
Источник: redhat
CVSS3: 7.5

Описание

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact and the issue is not currently planned to be addressed in future updates for Red Hat Enterprise Linux 7, hence, marked as Out-of-Support-Scope. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6xstreamOut of support scope
Red Hat CodeReady Studio 12xstreamAffected
Red Hat Data Grid 8xstreamAffected
Red Hat Decision Manager 7xstreamWill not fix
Red Hat Enterprise Linux 7xstreamOut of support scope
Red Hat Integration Camel K 1xstreamAffected
Red Hat JBoss A-MQ 6xstreamOut of support scope
Red Hat JBoss BRMS 5xstreamOut of support scope
Red Hat JBoss BRMS 6xstreamOut of support scope
Red Hat JBoss Data Grid 7xstreamOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400->CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2049783xstream: Injecting highly recursive collections or maps can cause a DoS

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 4 лет назад

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

CVSS3: 7.5
nvd
около 4 лет назад

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

CVSS3: 7.5
debian
около 4 лет назад

XStream is an open source java library to serialize objects to XML and ...

suse-cvrf
почти 4 года назад

Security update for xstream

suse-cvrf
почти 4 года назад

Security update for xstream

7.5 High

CVSS3