Server-Side Request Forgery (SSRF) in xstream - CVE-2021-39152
Published: March 22, 2023 / Updated: March 28, 2023
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Ubuntu
SUSE Linux Enterprise Module for Development Tools
openEuler
Fedora
Atlas eDiscovery Process Management
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
libxstream-java (Ubuntu package)
xstream (Red Hat package)
xstream
xstream-hibernate
xstream-benchmark
xstream-javadoc
xstream-parent
Storage Copy Data Management
IBM Tivoli Netcool Configuration Manager
JBoss Data Grid
How to mitigate CVE-2021-39152
Atlas eDiscovery Process Management - update to 6.0.3.9.7
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.3, 1.4.11.1-1+deb10u4build0.18.04.1, 1.4.18-2ubuntu0.1, 1.4.19-1ubuntu0.1
xstream (Red Hat package) - update to 1.3.1-16.el7_9
xstream - update to 1.4.18-1
xstream-hibernate - update to 1.4.18-1
xstream-benchmark - update to 1.4.18-1
xstream-javadoc - update to 1.4.18-1
xstream-parent - update to 1.4.18-1
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
xstream - update to 1.4.18-3.14.1
Storage Copy Data Management - update to 2.2.26.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
IBM Tivoli Netcool Configuration Manager - update to 6.4.2.17
JBoss Data Grid - update to 8.3.0
IBM Security Verify Governance - update to 10.0.1.0.2
Links to Public Exploits and PoC-codes
External References
- https://x-stream.github.io/CVE-2021-39152.html
- https://github.com/x-stream/xstream/security/advisories/GHSA-xw4p-crpj-vjx2
- https://security.netapp.com/advisory/ntap-20210923-0003/
- https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/
- https://www.debian.org/security/2021/dsa-5004
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
Related Security Bulletins
- Multiple vulnerabilities in xstream
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in IBM Atlas eDiscovery Process Management
- Multiple vulnerabilities in IBM Security Verify Governance
- Multiple vulnerabilities in IBM Tivoli Netcool Configuration Manager
- openEuler update for xstream
- Red Hat Enterprise Linux 7 update for xstream
- Multiple vulnerabilities in JBoss Data Grid 8.3
- SUSE update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 35 update for xstream
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Storage Copy Data Management