Executive brief
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Affected products
- Maven com.thoughtworks.xstream:xstream
Junglewise Threat Intelligence
CVE-2021-39150 · Severity: low · CVSS 3.1 · Published 2021-08-25
Technologies: com.thoughtworks.xstream:xstream (Maven). Vendors: Maven.
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host