CVE-2021-21343 is a deserialization vulnerability in XStream, a Java library used for XML serialization, affecting versions prior to 1.4.16. This flaw allows an unauthenticated attacker to manipulate the input stream during unmarshalling, leading to the deletion of files on the local host. With a CVSS score of 7.5 (High), it has a low attack complexity and requires no user interaction. While no active exploitation or public exploit code is reported, and community discussion is minimal, organizations using XStream's default security framework are at risk and should upgrade to version 1.4.16 or implement a strict whitelist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* | ||
< 5.15.14CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
5.16.0CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.16.0:*:*:*:*:*:*:* | ||
5.16.1CPE matchmatch criteria | cpe:2.3:a:apache:activemq:5.16.1:*:*:*:*:*:*:* | ||
< 5.5CPE matchmatch criteria | cpe:2.3:a:apache:jmeter:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Mar 22, 2021XStream: arbitrary file deletion on the local host via crafted input stream
Mar 12, 2021