CVE-2021-39144 — XStream Remote Code Execution Vulnerability
2023-03-10 • CISA Known Exploited Vulnerability
[event] XStream contains a remote code execution vulnerability that allows an attacker to manipulate the processed input stream and replace or inject objects that result in the execution of a local command on the server. This vulnerability can affect multiple products, including but not limited to VMware Cloud Foundation.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | XStream |
| Product | XStream |
| CWE | CWE-94, CWE-502 |
| CVE ID | CVE-2021-39144 |
| Date Added | 2023-03-10 |
| Due Date | 2023-03-31 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2023-03-31