CVE-2021-39139

Priority
Description
XStream is a simple library to serialize objects to XML and back again. In
affected versions this vulnerability may allow a remote attacker to load
and execute arbitrary code from a remote host only by manipulating the
processed input stream. A user is only affected if using the version out of
the box with JDK 1.7u21 or below. However, this scenario can be adjusted
easily to an external Xalan that works regardless of the version of the
Java runtime. No user is affected, who followed the recommendation to setup
XStream's security framework with a whitelist limited to the minimal
required types. XStream 1.4.18 uses no longer a blacklist by default, since
it cannot be secured for general purpose.
Notes
Package
Upstream:needs-triage
Ubuntu 18.04 LTS:needed
Ubuntu 20.04 LTS:needed
Ubuntu 21.10:needed
Ubuntu 22.04 LTS:not-affected (1.4.18-1)
Ubuntu 14.04 ESM:needed
Patches:
More Information

Updated: 2022-04-25 00:57:49 UTC (commit ecc1009cb19540b950de59270950018900f37f15)