CVE-2021-43859
Published on: Not Yet Published
Last Modified on: 08/09/2022 12:40:00 AM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.
- CVE-2021-43859 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
x-stream - xstream version < 1.4.19
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - April 2022 | www.oracle.com text/html |
![]() |
[SECURITY] [DLA 2924-1] libxstream-java security update | lists.debian.org text/html |
![]() |
XStream can cause a Denial of Service by injecting highly recursive collections or maps · Advisory · x-stream/xstream · GitHub | github.com text/html |
![]() |
Describe and fix CVE-2021-43859. · x-stream/[email protected] · GitHub | github.com text/html |
![]() |
[SECURITY] Fedora 34 Update: xstream-1.4.19-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
[SECURITY] Fedora 35 Update: xstream-1.4.19-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
XStream - CVE-2021-43859 | x-stream.github.io text/html |
![]() |
oss-security - Vulnerability in Jenkins | www.openwall.com text/html |
![]() |
Oracle Critical Patch Update Advisory - July 2022 | www.oracle.com text/html |
![]() |
Related QID Numbers
- 179078 Debian Security Update for libxstream-java (DLA 2924-1)
- 240241 Red Hat OpenShift Container Platform 5 Security Update (RHSA-2022:1420)
- 282371 Fedora Security Update for xstream (FEDORA-2022-ad5cf1c0dd)
- 282372 Fedora Security Update for xstream (FEDORA-2022-983a78275c)
- 690790 Free Berkeley Software Distribution (FreeBSD) Security Update for jenkins (0b0ad196-1ee8-4a98-89b1-4d5d82af49a9)
- 730360 Jenkins Denial of Service (DoS) Vulnerability (Jenkins Security Advisory 2022-02-09)
- 751873 OpenSUSE Security Update for xstream (openSUSE-SU-2022:0817-1)
- 753439 SUSE Enterprise Linux Security Update for xstream (SUSE-SU-2022:0817-1)
Known Affected Configurations (CPE V2.3)
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:commerce_guided_search:11.3.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0.0.5.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_intelligence_hub:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_diameter_intelligence_hub:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:16.0.6:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:17.0.4:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:18.0.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:19.0.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:retail_xstore_point_of_service:20.0.1:*:*:*:*:*:*:*:
- cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-43859 : XStream is an open source java library to serialize objects to XML and back again. Versions prior… twitter.com/i/web/status/1… | 2022-02-01 12:13:34 |