Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27911
HistoryNov 17, 2020 - 5:32 a.m.

Remote Code Execution (RCE)

2020-11-1705:32:23
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.974 High

EPSS

Percentile

99.9%

XStream is vulnerable to remote code execution (RCE). The processed stream at unmarshalling time contains type information to recreate the formerly written objects, and new instances are created based on these type information. The vulnerability allows an attacker to manipulate the processed input stream and replace or inject objects that can result in arbitrary shell commands execution.

References