• CVE-2021-21344

发布时间: 2022年9月30日

修改时间: 2022年9月30日

概要

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream s security framework with a whitelist limited to the minimal required types. If you rely on XStream s default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVSS v3 指标

NVD openEuler
CVSS评分 9.8 9.8
Attack Vector Network Network
Attack Complexity Low Low
Privileges Required None None
User Interaction None None
Scope Unchanged Unchanged
Confidentiality High High
Integrity High High
Availability High High

安全公告

公告名 概要 发布时间
KylinSec-SA-2022-2438 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream s security framework with a whitelist limited to the minimal required types. If you rely on XStream s default blacklist of the Security Framework, you will have to use at least version 1.4.16. 2022年9月30日

影响产品

产品 状态
KY3.4-4A mysql Unaffected
KY3.4-5 mysql Unaffected
KY3.5.1 mysql Unaffected