Executive brief
XStream is vulnerable to Remote Code Execution (RCE) via unsafe deserialization of untrusted data. An attacker can manipulate the processed XML input stream to inject objects that execute arbitrary local commands on the server, particularly when XStream's security framework is not configured with a strict whitelist.
Affected products
- XStream Project XStream versions prior to 1.4.18
- VMware Cloud Foundation
- VMware NSX Manager
Timeline
- 2021-08-22: disclosed: Initial vulnerability disclosure and XStream 1.4.18 release
- 2023-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-10: exploited: Confirmed active exploitation in the wild