External risk intelligence

XStream Deserialization Vulnerability Allows Server-Side Request Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2021-21342

XStream is a widely used serialization library embedded in many enterprise applications, including web servers, message brokers, and management portals. Because it processes XML input, it is frequently exposed to remote, unauthenticated inputs in web-facing services, APIs, and network-accessible application components, making public-internet reachability a common deployment pattern for affected products.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the XStream Java library could allow an attacker to execute arbitrary code on servers by manipulating input streams during data deserialization. This is a critical risk for applications that process XML data using XStream and have not configured its security framework to use a whitelist of allowed types.

  • Vulnerability allows remote code execution.
  • Impacts applications processing XML via XStream.
  • Confirm XStream usage and security configuration.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted XML input to an application that uses a vulnerable version of XStream for unmarshalling. This input can manipulate the processed stream to inject or replace objects, leading to a server-side request forgery. This can occur if the application has not configured XStream's security framework with a strict whitelist.

  • Attackers can reach unmarshalling code over the network.
  • Malicious XML input triggers object injection.
  • Server-side request forgery is a potential outcome.

Live Threat

Current exploitation, exposure, and threat context

When configured with XStream's default blacklist security framework, the processed stream at unmarshalling time can be manipulated by an attacker to inject or replace objects, potentially leading to a server-side request forgery when the input stream is processed.

  • Server-side requests could be forged.
  • Malicious objects could be injected into the stream.
  • Compromised server functionality may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The owners of applications that embed the XStream library are responsible for managing this vulnerability. The first step is to identify all systems utilizing XStream, assess their exposure to external input, and determine their criticality. Once ownership is confirmed, a remediation plan should be developed based on the identified risk.

  • Application owners should manage this issue.
  • Verify XStream usage and exposure first.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is XStream and how is it used?

XStream is a Java library designed to convert objects into XML and reconstruct them back into objects. Developers often embed it in software to handle data storage or communication between systems. Because it performs these conversions, it is commonly found in enterprise products, such as message brokers, management portals, and various business applications that need to process XML-based data streams.

What does CVE-2021-21342 mean for security?

This vulnerability involves insecure deserialization, categorized under CWE-502 and CWE-918. When XStream reconstructs objects from XML, it may trust the input too much. An attacker can craft malicious XML to inject unexpected objects into the process. This can lead to server-side request forgery (SSRF), where the server is tricked into making unauthorized requests to internal or external resources.

How can an attacker trigger this vulnerability?

An attacker triggers the vulnerability by sending a specially crafted XML input to a system using a vulnerable version of XStream. The bug occurs when the application processes this input without proper restrictions. Importantly, you are not at risk if you have already configured XStream's security framework to use a strict whitelist that limits the types of objects the library is allowed to create.

Do I need to worry about this if my app is internal?

According to Halo Surface Signal, this CVE is frequently found in internet-facing services like APIs and web-based management tools. While public-facing applications are at higher risk because they accept remote input, any application processing untrusted XML data—whether internal or external—is a potential target if the XStream security framework is not properly configured.

How should I respond to this threat?

Start by identifying all applications in your environment that rely on the XStream library. Check the version of XStream in use and verify your current security configuration. If you cannot update to a version that fixes the issue, ensure you have implemented a strict, minimal whitelist of allowed types within the XStream security framework to prevent the library from instantiating unauthorized objects.

References