CVE-2021-39146 is a high-severity arbitrary code execution vulnerability affecting XStream, a Java library for XML serialization, and products like Debian, Fedora, NetApp, and Oracle that utilize it. A remote attacker can exploit this by manipulating the input stream, leading to complete compromise of confidentiality, integrity, and availability. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and the vulnerability has garnered significant community discussion and media coverage, indicating potential for exploitation despite not being on the KEV catalog. Organizations are advised to implement XStream's security framework with a strict whitelist to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.18CPE matchmatch criteria | cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.