XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2704-1 | libxstream-java security update |
Debian DSA |
DSA-5004-1 | libxstream-java security update |
Github GHSA |
GHSA-7chv-rrw6-w6fc | XStream is vulnerable to a Remote Command Execution attack |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 29 May 2025 23:45:00 +0000
Fri, 23 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle retail Customer Insights
Xstream Xstream xstream |
|
| CPEs | cpe:2.3:a:oracle:retail_customer_insights:15.0.2:*:*:*:*:*:*:* cpe:2.3:a:oracle:retail_customer_insights:16.0.2:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Xstream Project
Xstream Project xstream |
Oracle retail Customer Insights
Xstream Xstream xstream |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-29T23:30:31.977Z
Reserved: 2021-03-30T00:00:00
Link: CVE-2021-29505
No data.
Status : Modified
Published: 2021-05-28T21:15:08.713
Modified: 2025-05-30T00:15:20.543
Link: CVE-2021-29505
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA