CVE-2021-29505 is a high-severity vulnerability in XStream versions prior to 1.4.17, a Java XML serialization library, allowing remote attackers with sufficient privileges to execute arbitrary commands by manipulating input streams. This vulnerability affects various products including Debian, Fedora, NetApp, and Oracle. With a CVSS score of 8.8 (High) and an EPSS score of 0.90769, it presents a significant risk, enabling complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit intelligence indicates the existence of Nuclei templates for detection, and it has garnered community discussion and media coverage, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.17CPE matchmatch criteria | cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.