Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-67819
HistoryAug 23, 2021 - 12:00 a.m.

XStream SSRF Vulnerability (CNVD-2021-67819)

2021-08-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
15

0.012 Low

EPSS

Percentile

85.6%

XStream is an open source Java class library that is mainly used to serialize objects to XML (JSON) or deserialize them to objects.XStream 1.4.17 and previous versions have a server-side request forgery vulnerability, which can be used by remote attackers to submit special requests that can obtain sensitive information.

CPENameOperatorVersion
xstream xstreamle1.4.17