Candidate: CVE-2021-29505 PublicDate: 2021-05-28 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-29505 https://github.com/x-stream/xstream/security/advisories/GHSA-7chv-rrw6-w6fc Description: XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_libxstream-java: upstream_libxstream-java: needs-triage trusty_libxstream-java: ignored (out of standard support) trusty/esm_libxstream-java: needed xenial_libxstream-java: ignored (out of standard support) bionic_libxstream-java: needed focal_libxstream-java: needed groovy_libxstream-java: ignored (reached end-of-life) hirsute_libxstream-java: ignored (reached end-of-life) impish_libxstream-java: needed jammy_libxstream-java: not-affected (1.4.17) devel_libxstream-java: not-affected (1.4.17)