Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31796
HistoryAug 24, 2021 - 6:27 a.m.

Remote Code Execution (RCE)

2021-08-2406:27:20
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20

0.274 Low

EPSS

Percentile

96.8%

xstream is vulnerable to remote code execution. The vulnerability exists due to the usage of an insecure default blacklist which does not cover all the excluded XStream security framework.

References