{"cves":[{"id":"CVE-2020-18774","published":"2021-08-23T22:15:00","updated_at":"2025-09-15T18:34:42.793608+00:00","description":"\nA float point exception in the printLong function in tags_int.cpp of Exiv2\n0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted\ntif file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"doesn't appear to be a fix from upstream as of 2025-09-10"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-18774"],"bugs":["https://github.com/Exiv2/exiv2/issues/759"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-18773","published":"2021-08-23T22:15:00","updated_at":"2025-09-15T20:24:25.535260+00:00","description":"\nAn invalid memory access in the decode function in iptc.cpp of Exiv2\n0.27.99.0 allows attackers to cause a denial of service (DOS) via a crafted\ntif file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"doesn't appear to be a fix from upstream as of 2025-09-10"}],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-18773"],"bugs":["https://github.com/Exiv2/exiv2/issues/760"],"patches":{"exiv2":[]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred [2025-02-20]","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-18771","published":"2021-08-23T22:15:00","updated_at":"2026-03-18T22:54:23.958227+00:00","description":"\nExiv2 0.27.99.0 has a global buffer over-read in\nExiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can\nresult in an information leak.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/Exiv2/exiv2/issues/756","https://www.cve.org/CVERecord?id=CVE-2020-18771","https://ubuntu.com/security/notices/USN-8103-1"],"bugs":[""],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/pull/757","upstream: https://github.com/Exiv2/exiv2/pull/758"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.27.2-8ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.27.2-6","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.25-3.1ubuntu0.18.04.11+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.25-2.1ubuntu16.04.7+esm5","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8103-1"],"notices":[{"id":"USN-8103-1","title":"Exiv2 vulnerabilities","summary":"Several security issues were fixed in Exiv2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-18T02:55:39.370642","description":"It was discovered that Exiv2 did not correctly handle reading certain\nbuffers. An attacker could possibly use this issue to leak sensitive\ninformation. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04\nLTS. (CVE-2020-18771)\n\nWen Cheng discovered that Exiv2 did not correctly handle certain memory\nallocation. If a user or system were tricked into opening a specially\ncrafted file, an attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.\n(CVE-2020-18899)\n\nIt was discovered that Exiv2 did not correctly handle writing certain\nmetadata. If a user or system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2025-54080)\n\nIt was discovered that Exiv2 did not correctly handle parsing certain\nmetadata. If a user or system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,\nUbuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-55304)\n\nIt was discovered that Exiv2 did not correctly handle parsing certain\nimages. If a user or system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to cause a denial of\nservice. (CVE-2026-25884)\n\nIt was discovered that Exiv2 did not correctly handle previewing certain\nimages. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2026-27596)\n\nIt was discovered that Exiv2 did not correctly handle certain integer\narithmetic. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2026-27631)","is_hidden":false,"release_packages":{"bionic":[{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.11+esm1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-3.1ubuntu0.18.04.11+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-14","version":"0.25-3.1ubuntu0.18.04.11+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-dev","version":"0.25-3.1ubuntu0.18.04.11+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-doc","version":"0.25-3.1ubuntu0.18.04.11+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"exiv2","version":"0.27.2-8ubuntu2.7+esm1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.2-8ubuntu2.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-27","version":"0.27.2-8ubuntu2.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-dev","version":"0.27.2-8ubuntu2.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-doc","version":"0.27.2-8ubuntu2.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"exiv2","version":"0.27.5-3ubuntu1.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.5-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-27","version":"0.27.5-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.5-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.1","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.5-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.5-3ubuntu1.1","pocket":"security"}],"noble":[{"name":"exiv2","version":"0.27.6-1ubuntu0.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.27.6-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-27","version":"0.27.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-dev","version":"0.27.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-doc","version":"0.27.6-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.27.6-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"exiv2","version":"0.28.5+dfsg-1ubuntu0.1","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.28.5+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-28","version":"0.28.5+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-data","version":"0.28.5+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-dev","version":"0.28.5+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libexiv2-doc","version":"0.28.5+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":"https://launchpad.net/ubuntu/+source/exiv2/0.28.5+dfsg-1ubuntu0.1","pocket":"security"}],"xenial":[{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm5","description":"EXIF/IPTC/XMP metadata manipulation tool","is_source":true},{"name":"exiv2","version":"0.25-2.1ubuntu16.04.7+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-14","version":"0.25-2.1ubuntu16.04.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-dev","version":"0.25-2.1ubuntu16.04.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"},{"name":"libexiv2-doc","version":"0.25-2.1ubuntu16.04.7+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/exiv2","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-27631","CVE-2026-27596","CVE-2025-54080","CVE-2026-25884","CVE-2025-55304","CVE-2020-18771","CVE-2020-18899"]}]},{"id":"CVE-2020-18735","published":"2021-08-23T21:15:00","updated_at":"2025-07-11T07:43:54.342777+00:00","description":"\nA heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS\nProject v0.1.0 causes the DDS subscriber server to crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://projects.eclipse.org/projects/iot.cyclonedds","https://github.com/eclipse-cyclonedds/cyclonedds","https://github.com/eclipse-cyclonedds/cyclonedds/issues/501","https://www.cve.org/CVERecord?id=CVE-2020-18735"],"bugs":[""],"patches":{"cyclonedds":[]},"tags":{},"packages":[{"name":"cyclonedds","source":"https://ubuntu.com/security/cve?package=cyclonedds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cyclonedds","debian":"https://tracker.debian.org/pkg/cyclonedds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-18734","published":"2021-08-23T21:15:00","updated_at":"2025-07-11T07:43:54.342777+00:00","description":"\nA stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS\nProject v0.1.0 causes the DDS subscriber server to crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://projects.eclipse.org/projects/iot.cyclonedds","https://github.com/eclipse-cyclonedds/cyclonedds","https://github.com/eclipse-cyclonedds/cyclonedds/issues/476","https://www.cve.org/CVERecord?id=CVE-2020-18734"],"bugs":[""],"patches":{"cyclonedds":[]},"tags":{},"packages":[{"name":"cyclonedds","source":"https://ubuntu.com/security/cve?package=cyclonedds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cyclonedds","debian":"https://tracker.debian.org/pkg/cyclonedds","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22253","published":"2021-08-23T20:15:00","updated_at":"2025-08-25T23:32:59.987291+00:00","description":"\nImproper authorization in GitLab EE affecting all versions since 13.4\nallowed a user who previously had the necessary access to trigger\ndeployments to protected environments under specific conditions after the\naccess has been removed","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/gitlab/-/issues/323794","https://hackerone.com/reports/1113783","https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22253.json","https://www.cve.org/CVERecord?id=CVE-2021-22253"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22252","published":"2021-08-23T20:15:00","updated_at":"2025-08-25T23:32:59.987291+00:00","description":"\nA confusion between tag and branch names in GitLab CE/EE affecting all\nversions since 13.7 allowed a Developer to access protected CI variables\nwhich should only be accessible to Maintainers","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22252.json","https://gitlab.com/gitlab-org/gitlab/-/issues/330364","https://hackerone.com/reports/1186135","https://www.cve.org/CVERecord?id=CVE-2021-22252"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code introduced later","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22251","published":"2021-08-23T20:15:00","updated_at":"2025-08-25T23:32:59.987291+00:00","description":"\nImproper validation of invited users' email address in GitLab EE affecting\nall versions since 12.2 allowed projects to add members with email address\ndomain that should be blocked by group settings","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22251.json","https://gitlab.com/gitlab-org/gitlab/-/issues/14004","https://hackerone.com/reports/679567","https://www.cve.org/CVERecord?id=CVE-2021-22251"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22249","published":"2021-08-23T20:15:00","updated_at":"2025-08-25T23:32:55.521192+00:00","description":"\nA verbose error message in GitLab EE affecting all versions since 12.2\ncould disclose the private email address of a user invited to a group","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22249.json","https://hackerone.com/reports/1204320","https://gitlab.com/gitlab-org/gitlab/-/issues/331857","https://www.cve.org/CVERecord?id=CVE-2021-22249"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-22248","published":"2021-08-23T20:15:00","updated_at":"2025-08-25T23:32:55.521192+00:00","description":"\nImproper authorization on the pipelines page in GitLab CE/EE affecting all\nversions since 13.12 allowed unauthorized users to view some pipeline\ninformation for public projects that have access to pipelines restricted to\nmembers only","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22248.json","https://gitlab.com/gitlab-org/gitlab/-/issues/336074","https://www.cve.org/CVERecord?id=CVE-2021-22248"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code intrododuced later","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2021-39152","published":"2021-08-23T19:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to request\ndata from internal resources that are not publicly available only by\nmanipulating the processed input stream with a Java runtime version 14 to\n8. No user is affected, who followed the recommendation to setup XStream's\nsecurity framework with a whitelist limited to the minimal required types.\nIf you rely on XStream's default blacklist of the [Security\nFramework](https://x-stream.github.io/security.html#framework), you will\nhave to use at least version 1.4.18.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-xw4p-crpj-vjx2","https://x-stream.github.io/CVE-2021-39152.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39152"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39150","published":"2021-08-23T19:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to request\ndata from internal resources that are not publicly available only by\nmanipulating the processed input stream with a Java runtime version 14 to\n8. No user is affected, who followed the recommendation to setup XStream's\nsecurity framework with a whitelist limited to the minimal required types.\nIf you rely on XStream's default blacklist of the [Security\nFramework](https://x-stream.github.io/security.html#framework), you will\nhave to use at least version 1.4.18.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-cxfm-5m4g-x7xp","https://x-stream.github.io/CVE-2021-39150.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39150"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39140","published":"2021-08-23T19:15:00","updated_at":"2025-08-25T23:40:06.788178+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to\nallocate 100% CPU time on the target system depending on CPU type or\nparallel execution of such a payload resulting in a denial of service only\nby manipulating the processed input stream. No user is affected, who\nfollowed the recommendation to setup XStream's security framework with a\nwhitelist limited to the minimal required types. XStream 1.4.18 uses no\nlonger a blacklist by default, since it cannot be secured for general\npurpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-6wf9-jmg9-vxcc","https://x-stream.github.io/CVE-2021-39140.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39140"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39154","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-6w62-hx7r-mw68","https://x-stream.github.io/CVE-2021-39154.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39154"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39153","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream, if using the version out of the box with Java\nruntime version 14 to 8 or with JavaFX installed. No user is affected, who\nfollowed the recommendation to setup XStream's security framework with a\nwhitelist limited to the minimal required types. XStream 1.4.18 uses no\nlonger a blacklist by default, since it cannot be secured for general\npurpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-2q8x-2p7f-574v","https://x-stream.github.io/CVE-2021-39153.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39153"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39151","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-hph2-m3g5-xxv4","https://x-stream.github.io/CVE-2021-39151.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39151"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39149","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-3ccq-5vw3-2p6x","https://x-stream.github.io/CVE-2021-39149.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39149"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39148","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:11.591992+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-qrx8-8545-4wg2","https://x-stream.github.io/CVE-2021-39148.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39148"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39147","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:06.788178+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-h7v4-7xg3-hxcc","https://x-stream.github.io/CVE-2021-39147.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39147"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]},{"id":"CVE-2021-39146","published":"2021-08-23T18:15:00","updated_at":"2025-08-25T23:40:06.788178+00:00","description":"\nXStream is a simple library to serialize objects to XML and back again. In\naffected versions this vulnerability may allow a remote attacker to load\nand execute arbitrary code from a remote host only by manipulating the\nprocessed input stream. No user is affected, who followed the\nrecommendation to setup XStream's security framework with a whitelist\nlimited to the minimal required types. XStream 1.4.18 uses no longer a\nblacklist by default, since it cannot be secured for general purpose.","ubuntu_description":"","notes":[{"author":"sahnaseredini","note":"for `trusty` and `xenial`, the code is not present and the\navailable pocs cannot be exploited"}],"codename":null,"priority":"medium","cvss3":8.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/x-stream/xstream/security/advisories/GHSA-p8pq-r894-fm8f","https://x-stream.github.io/CVE-2021-39146.html","https://ubuntu.com/security/notices/USN-5946-1","https://www.cve.org/CVERecord?id=CVE-2021-39146"],"bugs":[""],"patches":{"libxstream-java":[]},"tags":{},"packages":[{"name":"libxstream-java","source":"https://ubuntu.com/security/cve?package=libxstream-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxstream-java","debian":"https://tracker.debian.org/pkg/libxstream-java","statuses":[{"release_codename":"focal","status":"released","description":"1.4.11.1-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.18-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.4.11.1-1+deb10u4build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-5946-1"],"notices":[{"id":"USN-5946-1","title":"XStream vulnerabilities","summary":"Several security issues were fixed in XStream.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-03-13T10:57:59.356035","description":"Lai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2021-39140)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04\nLTS. (CVE-2021-39139, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145,\nCVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149,\nCVE-2021-39151, CVE-2021-39153, CVE-2021-39154)\n\nIt was discovered that XStream incorrectly handled certain inputs. If\na user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2021-39150, CVE-2021-39152)\n\nLai Han discovered that XStream incorrectly handled certain inputs.\nIf a user or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2022-41966)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.7-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.18-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.18-2ubuntu0.1","pocket":"security"}],"xenial":[{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.8-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1+deb10u4build0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1+deb10u4build0.18.04.1","pocket":"security"}],"kinetic":[{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.19-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.19-1ubuntu0.1","pocket":"security"}],"focal":[{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","description":"Java library to serialize objects to XML and back again","is_source":true},{"name":"libxstream-java","version":"1.4.11.1-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libxstream-java","version_link":"https://launchpad.net/ubuntu/+source/libxstream-java/1.4.11.1-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-39141","CVE-2021-39150","CVE-2021-39139","CVE-2021-39147","CVE-2021-39152","CVE-2021-39149","CVE-2021-39148","CVE-2022-41966","CVE-2021-39144","CVE-2021-39146","CVE-2021-39151","CVE-2021-39154","CVE-2021-39145","CVE-2021-39140","CVE-2021-39153"]}]}],"offset":41460,"limit":20,"total_results":79316}