VDB
BDU%3A2021-03903
BDU%3A2021-03903
PUBLISHED
CVSS 9 CRITICAL
Уязвимость Java-библиотеки для преобразования объектов в XML или JSON формат Xstream, связанная с недостатками механизма десериализации, позволяющая нарушителю выполнить произвольные команды
Risk Scores
CVSS 2.0
9
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Сообщество свободного программного обеспечения, Xstream Project, АО «Концерн ВНИИНС» | Red Hat Enterprise Linux, Debian GNU/Linux, Red Hat JBoss Fuse, Red Hat Descision Manager, CodeReady Studio, Data Grid, Red Hat Process Automation, Red Hat Integration Camel K, XStream, Red Hat Integration Camel Quarkus, ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Aug 4, 2021 CVE Published
- Nov 21, 2023 CVE Updated
References
- https://github.com/x-stream/xstream/commit/24fac82191292c6ae25f94508d28b9823f83624f url
- https://github.com/x-stream/xstream/security/advisories/GHSA-7chv-rrw6-w6fc url
- https://lists.apache.org/thread.html/r8ee51debf7fd184b6a6b020dc31df25118b0aa612885f12fbe77f04f@%3Cdev.jmeter.apache.org%3E url
- https://lists.debian.org/debian-lts-announce/2021/07/msg00004.html url
- https://security.netapp.com/advisory/ntap-20210708-0007/ url
- https://nvd.nist.gov/vuln/detail/CVE-2021-29505 url
- https://access.redhat.com/security/cve/cve-2021-29505 url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url