Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-67821
HistoryAug 23, 2021 - 12:00 a.m.

XStream SSRF Vulnerability (CNVD-2021-67821)

2021-08-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
xstream
ssrf
vulnerability
java
xml
json
serialization
deserialization
remote attackers
sensitive information

EPSS

0.013

Percentile

86.1%

XStream is an open source Java class library that is mainly used to serialize objects to XML (JSON) or deserialize them to objects.XStream 1.4.17 and previous versions have a server-side request forgery vulnerability, which can be used by remote attackers to submit special requests that can obtain sensitive information.