Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-21349
HistoryMar 23, 2021 - 12:00 a.m.

CVE-2021-21349

2021-03-2300:00:00
ubuntu.com
ubuntu.com
16

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

0.015 Low

EPSS

Percentile

87.0%

XStream is a Java library to serialize objects to XML and back again. In
XStream before version 1.4.16, there is a vulnerability which may allow a
remote attacker to request data from internal resources that are not
publicly available only by manipulating the processed input stream. No user
is affected, who followed the recommendation to setup XStream’s security
framework with a whitelist limited to the minimal required types. If you
rely on XStream’s default blacklist of the Security Framework, you will
have to use at least version 1.4.16.

Bugs

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

0.015 Low

EPSS

Percentile

87.0%