'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2021-29505: XStream 1.4.16 Remote Code Execution Vulnerability
Severity:high
CVE ID:CVE-2021-29505
Descripiton:
|
XStream is a lightweight, easy-to-use open source Java class library of the XStream (XStream) team, which is mainly used to sequence the object serial into XML (JSON) or reverse sequences. XStream uses a blacklist mechanism to defend against deserialization vulnerabilities when parsing XML text, but its version 1.4.16 and earlier blacklists have flaws. Attackers can use `sun.rmi.registry.RegistryImpl_Stub` to construct RMI requests and execute arbitrary Order. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.