NVD disclosure day

Published threat advisories for March 23, 2021

CVE advisoryCRITICAL

CVE-2021-21351

XStream Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the XStream Java library could allow remote attackers to execute arbitrary code by manipulating input streams. This is a critical risk for applications processing untrusted XML data, especially if XStream's security framework is not configured with a restrictive whitelist. Confirming XStream usage an

CVE advisoryCRITICAL

CVE-2021-21347

XStream Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the XStream Java library may allow a remote attacker to execute arbitrary code by manipulating input streams. This could impact systems using XStream's default security configuration, potentially affecting system data and services. Readers should confirm XStream usage and assess exposure.

CVE advisoryCRITICAL

CVE-2021-21345

XStream XML Deserialization Command Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the XStream Java serialization library may allow a remote attacker to execute host commands by manipulating processed input. Users who rely on XStream's default security settings are vulnerable if they have not updated to a patched version.

CVE advisoryCRITICAL

CVE-2021-21344

XStream Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in the XStream Java serialization library allows remote attackers to execute arbitrary code by manipulating input streams. This risk is amplified when XStream's security framework is not configured with a restrictive whitelist, potentially impacting applications that process untrusted XML input

CVE advisoryCRITICAL

CVE-2021-21342

XStream Deserialization Vulnerability Allows Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

The XStream Java library has a vulnerability that allows for server-side request forgery when processing untrusted XML input. An attacker can manipulate the input stream to inject or replace objects during deserialization, leading to the execution of arbitrary code if XStream's security framework is not properly config