Miggo Logo

CVE-2021-39144:
XStream is vulnerable to a Remote Command Execution attack

8.6

CVSS Score
3.1

Basic Information

EPSS Score
0.99973%
Published
8/25/2021
Updated
6/27/2023
KEV Status
Yes
Technology
TechnologyJava

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
com.thoughtworks.xstream:xstreammaven< 1.4.181.4.18

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t T** vuln*r**ility m*y *llow * r*mot* *tt**k*r **s su**i*i*nt ri**ts to *x**ut* *omm*n*s o* t** *ost only *y m*nipul*tin* t** pro**ss** input str**m. No us*r is *****t**, w*o *ollow** t** r**omm*n**tion to s*tup XStr**m's s**urity *r*m*work

Reasoning

No *n*lysis *v*il**l*