Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-29505

Опубликовано: 28 мая 2021
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 6.5
CVSS3: 7.5

Описание

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.4.17
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

1.4.17
esm-apps/noble

not-affected

1.4.17
esm-apps/xenial

needs-triage

esm-infra-legacy/trusty

needed

focal

ignored

end of standard support, was needed
groovy

ignored

end of life

Показывать по

EPSS

Процентиль: 100%
0.90769
Критический

6.5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 4 лет назад

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

CVSS3: 7.5
nvd
больше 4 лет назад

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

CVSS3: 7.5
debian
больше 4 лет назад

XStream is software for serializing Java objects to XML and back again ...

suse-cvrf
больше 4 лет назад

Security update for xstream

suse-cvrf
больше 4 лет назад

Security update for xstream

EPSS

Процентиль: 100%
0.90769
Критический

6.5 Medium

CVSS2

7.5 High

CVSS3