GHSA-56p8-3fh9-4cvq
MEDIUMCVE-2021-21348The vulnerability may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types.
- Affected
- >=0, <5.15.14, >=5.16.0, >=5.16.1
- Fixed in
- 1.4.16
- Published
- 2021-03-22
- Source
- github