HIGH · 7.5

CVE-2021-43859

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU ...

Vulnerability Description

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
JenkinsJenkins< 2.319.3
XstreamXstream< 1.4.19
FedoraprojectFedora34
DebianDebian Linux9.0
OracleCommerce Guided Search11.3.2
OracleCommunications Brm - Elastic Charging Engine< 12.0.0.4.6
OracleCommunications Cloud Native Core Automated Test Suite1.9.0
OracleCommunications Diameter Intelligence Hub>= 8.0.0, <= 8.1.0
OracleCommunications Policy Management12.6.0.0.0
OracleFlexcube Private Banking12.1.0
OracleRetail Xstore Point Of Service16.0.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-43859?

CVE-2021-43859 is a vulnerability with a CVSS score of 7.5 (HIGH). XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU ...

How severe is CVE-2021-43859?

CVE-2021-43859 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-43859?

Check the references section above for vendor advisories and patch information. Affected products include: Jenkins Jenkins, Xstream Xstream, Fedoraproject Fedora, Debian Debian Linux, Oracle Commerce Guided Search.