Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31799
HistoryAug 24, 2021 - 6:43 a.m.

Remote Code Execution (RCE)

2021-08-2406:43:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
remote code execution
xstream
insecure default blacklist
security framework

EPSS

0.03

Percentile

91.1%

xstream is vulnerable to remote code execution. The vulnerability exists due to the usage of an insecure default blacklist which does not cover all the excluded XStream security framework.