CVE-2021-39144 is a critical remote code execution (RCE) vulnerability affecting XStream, a Java library for XML serialization, impacting various products including Debian, Fedora, NetApp, Oracle, and VMware. With a CVSS score of 8.5 (HIGH), this vulnerability allows authenticated remote attackers to execute arbitrary commands by manipulating processed input streams, leading to severe impacts on confidentiality, integrity, and availability. This flaw is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and the availability of Metasploit modules and Nuclei templates, garnering significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.18CPE matchmatch criteria | cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.