Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | XStream before 1.4.16 is susceptible to remote code execution. An attacker can load and execute arbitrary code from a remote host via manipulating the processed input stream, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-21351.yaml | POC Details |
| 2 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E6%A1%86%E6%9E%B6%E6%BC%8F%E6%B4%9E/XStream%20%E5%8F%8D%E5%BA%8F%E5%88%97%E5%8C%96%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C%E6%BC%8F%E6%B4%9E%20CVE-2021-21351.md | POC Details |
| 3 | https://github.com/vulhub/vulhub/blob/master/xstream/CVE-2021-21351/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-21341 | 7.5 HIGH | XStream can cause a Denial of Service |
| CVE-2021-21346 | 6.1 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21347 | 6.1 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21349 | 6.1 MEDIUM | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data s |
| CVE-2021-21345 | 5.8 MEDIUM | XStream is vulnerable to a Remote Command Execution attack |
| CVE-2021-21342 | 5.3 MEDIUM | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data s |
| CVE-2021-21343 | 5.3 MEDIUM | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling a |
| CVE-2021-21344 | 5.3 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
| CVE-2021-21348 | 5.3 MEDIUM | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos |
| CVE-2021-21350 | 5.3 MEDIUM | XStream is vulnerable to an Arbitrary Code Execution attack |
No comments yet