Loading HuntDB...

XStream Remote Code Execution Vulnerability

Added March 10, 2023 Due March 31, 2023 CVE-2021-39144
Overdue XStream / XStream CWE-94 CWE-502

Description

XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
7 months, 2 weeks ago