'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2021-21351: XStream Deserialization Remote Code Execution Vulnerability
Severity:critical
CVE ID:CVE-2021-21351
| Descripiton:
|
XStream is a lightweight, easy-to-use open source Java class library of the XStream (XStream) team, which is mainly used to sequence the object serial into XML (JSON) or reverse sequences. A code issue vulnerability existed in XStream prior to 1.4.16 that could allow an attacker to load and execute arbitrary code on a remote host simply by manipulating the processed input stream. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.