CVE-2021-39144

Confirmed PUBLISHED

XStream is vulnerable to a Remote Command Execution attack

x-stream · xstream
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.5 High EPSS 98.1%

At a Glance

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

cisa metasploit nuclei_scanner
CVE Published
Aug 23, 2021
Exploitation Reported
Mar 10, 2023
CVSS
8.5 High
EPSS
98.1%
Remote No user interaction

Affected Versions

Vendor Product Version Status
x-stream
xstream

< 1.4.18

Affected

CVE References

Show 7 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.