CVE-2021-39146: Deserialization of Untrusted Data
(updated )
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. Users who followed the recommendation to setup XStream’s security framework with a allow list limited to the minimal required types are not impacted.
References
Detect and mitigate CVE-2021-39146 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →