CVE-2021-21342 is a critical server-side request forgery (SSRF) vulnerability affecting XStream, a Java library used for XML serialization, and products utilizing it such as Apache, Debian, and Oracle. This flaw allows an unauthenticated attacker to manipulate the input stream during unmarshalling, leading to the creation of malicious objects and subsequent SSRF. With a CVSS score of 9.1, it presents a high risk due to its network-based attack vector and low complexity, potentially resulting in complete compromise of confidentiality and integrity. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations are urged to update to XStream version 1.4.16 or implement a strict whitelist for type serialization.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* | ||
< 5.15.14CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.16.0:*:*:*:*:*:*:* | ||
5.16.1CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.16.1:*:*:*:*:*:*:* | ||
< 5.5CPE matchmatch criteria | cpe:2.3:a:apache:jmeter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.