Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31793
HistoryAug 24, 2021 - 6:01 a.m.

Remote Code Execution (RCE)

2021-08-2406:01:08
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13

0.025 Low

EPSS

Percentile

90.1%

xstream is vulnerable to remote code execution. The vulnerability exists due to the usage of an insecure default blacklist which does not cover all the excluded XStream security framework.