Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-67828
HistoryAug 23, 2021 - 12:00 a.m.

XStream Arbitrary Code Execution Vulnerability (CNVD-2021-67828)

2021-08-2300:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.254 Low

EPSS

Percentile

96.7%

XStream is an open source Java class library that is mainly used to serialize objects to XML (JSON) or deserialize them to objects.XStream 1.4.17 and earlier versions have an arbitrary code execution vulnerability that can be exploited by attackers to cause arbitrary code execution.

CPENameOperatorVersion
xstream xstreamle1.4.17