XStream是XStream(Xstream)团队的一个轻量级的、简单易用的开源Java类库,它主要用于将对象序列化成XML(JSON)或反序列化为对象。 XStream 1.4.16 之前版本存在代码问题漏洞,攻击者可利用该漏洞仅通过操作已处理的输入流来执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-21341 | 7.5 HIGH | XStream can cause a Denial of Service |
| CVE-2021-21346 | 6.1 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21347 | 6.1 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21349 | 6.1 MEDIUM | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data s |
| CVE-2021-21345 | 5.8 MEDIUM | XStream is vulnerable to a Remote Command Execution attack |
| CVE-2021-21351 | 5.4 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21342 | 5.3 MEDIUM | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data s |
| CVE-2021-21343 | 5.3 MEDIUM | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling a |
| CVE-2021-21344 | 5.3 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21348 | 5.3 MEDIUM | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos |
No comments yet