Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29790
HistoryMar 23, 2021 - 7:01 a.m.

Remote Code Execution

2021-03-2307:01:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
xstream
vulnerability
remote code execution
input stream
security framework
attacker
arbitrary code
remote server

EPSS

0.018

Percentile

88.3%

xstream is vulnerable to remote code execution. The vulnerability exists because it relies on XStream’s default blacklist of the Security Framework, allowing an attacker to manipulate the processed input stream and replace or inject objects, that result in execution of arbitrary code loaded from a remote server.

References