Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-67827
HistoryAug 23, 2021 - 12:00 a.m.

XStream Arbitrary Code Execution Vulnerability (CNVD-2021-67827)

2021-08-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
19
xstream
java
serialization
xml
json
vulnerability
code execution
attackers

EPSS

0.967

Percentile

99.7%

XStream is an open source Java class library that is mainly used to serialize objects to XML (JSON) or deserialize them to objects.XStream 1.4.17 and earlier versions have an arbitrary code execution vulnerability that can be exploited by attackers to cause arbitrary code execution.