Junglewise Threat Intelligence

CVE-2021-39144: XStream is vulnerable to a Remote Command Execution attack

CVE-2021-39144 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2021-08-25

Technologies: com.thoughtworks.xstream:xstream (Maven), VMware Cloud Foundation. Vendors: VMware, Maven.

Executive brief

XStream is vulnerable to Remote Code Execution (RCE) via unsafe deserialization of untrusted data. An attacker can manipulate the processed XML input stream to inject objects that execute arbitrary local commands on the server, particularly when XStream's security framework is not configured with a strict whitelist.

Affected products

  • XStream Project XStream versions prior to 1.4.18
  • VMware Cloud Foundation
  • VMware NSX Manager

Timeline

  • 2021-08-22: disclosed: Initial vulnerability disclosure and XStream 1.4.18 release
  • 2023-03-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-03-10: exploited: Confirmed active exploitation in the wild

Related threats