THREATPORT/VULNERABILITY/CVE-2022-41966
HIGH SEVERITY

CVE-2022-41966

Xstream vulnerability

CVSS
8.2
EPSS
8.7%
EPSS pct
95th
Exploited
No known
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only as default map or set, is to change the default implementation of java.util.Map and java.util per the code example in the referenced advisory. However, this implies that your application does not care about the implementation of the map and all elements are comparable.
Affected vendor
Xstream
Affected product
Xstream
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Weakness type (CWE)
  • CWE-120 — Classic Buffer Overflow
  • CWE-121 — Stack-based Buffer Overflow
  • CWE-502 — Deserialization of Untrusted Data
  • CWE-674 — Uncontrolled Recursion
Published
2022-12-28

Risk analysis

Based on its CVSS vector, this vulnerability is exploitable over the network, low attack complexity, requiring no privileges, no user interaction. Successful exploitation leads to low impact to integrity, high impact to availability.

Its EPSS score of 8.7% reflects a lower probability of exploitation activity in the wild over the next 30 days, placing it above 95% of all scored CVEs.

Check your external exposure to CVE-2022-41966

  • Confirm whether Xstream Xstream is running on any internet-facing host or subdomain.
  • Match discovered service fingerprints against the version affected by CVE-2022-41966.
  • Prioritise remediation if the asset is public, business-critical, or near authentication/payment flows.

How ThreatPort helps with CVE-2022-41966

ThreatPort's external attack surface scanner checks your internet-facing assets — agentlessly, from the outside in — for the exposed services and versions that CVE-2022-41966 affects, then prioritises the finding by real risk using CISA KEV and FIRST.org EPSS.

Run a free external exposure scan

Are you exposed to CVE-2022-41966?

Run an instant, non-intrusive external scan to check your attack surface for CVE-2022-41966.

Start free scan

No credit card. Agentless.