Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-29505

Опубликовано: 28 мая 2021
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 6.5
CVSS3: 7.5

Описание

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

1.4.17
esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

not-affected

1.4.17
esm-apps/noble

not-affected

1.4.17
esm-apps/resolute

not-affected

1.4.17
esm-apps/xenial

ignored

end of ESM support, was needs-triage
esm-infra-legacy/trusty

needed

Показывать по

EPSS

Процентиль: 100%
0.77735
Высокий

6.5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

CVSS3: 7.5
nvd
около 5 лет назад

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

CVSS3: 7.5
debian
около 5 лет назад

XStream is software for serializing Java objects to XML and back again ...

suse-cvrf
около 5 лет назад

Security update for xstream

suse-cvrf
около 5 лет назад

Security update for xstream

EPSS

Процентиль: 100%
0.77735
Высокий

6.5 Medium

CVSS2

7.5 High

CVSS3