References https://it.ruc.edu.cn/wlaq/c597ca0992b4440ba43000ed10421475.htm https://www.secrss.com/articles/50473 https://download.sangfor.com.cn/bc452bec412b4fe2bdbbc673bb5ae00f.pdf https://www.huaweicloud.com/notice/20221229151430378.html https://www.venustech.com.cn/new_type/aqtg/20221229/25008.html https://www.h3c.com/cn/d_202302/1782227_30003_0.htm https://isecurity.huawei.com/sec/web/viewAlert.do?id=2445 http://ssrc.chinaredflag.cn/index/bug/info/id/10656 https://www.iovz.com/announce-details.html?id=10 https://avd.aliyun.com/product?prod=xstream https://nvd.nist.gov/vuln/detail/cve-2022-41966 https://x-stream.github.io/CVE-2022-41966.html https://access.redhat.com/security/cve/cve-2022-41966 https://github.com/advisories/GHSA-j563-grx4-pjpv https://stackoverflow.com/questions/75530160/is-geoserver-library-vulnerable-due-to-this-cve-2022-41966-which-is-on-xstream-c https://www.tenable.com/cve/CVE-2022-41966/plugins https://www.suse.com/security/cve/CVE-2022-41966.html https://www.sangfor.com/farsight-labs-threat-intelligence/cybersecurity/cve-2022-41966-xstream-denial-of-service-vulnerability https://groups.google.com/g/xstream-user/c/Uc3JNxL4dnA https://quickview.cloudapps.cisco.com/quickview/bug/CSCwe02490
Related VulnerabilitiesPoCCVE-2013-7285: XStream <1.4.6/1.4.10 - Remote Code ExecutionPoCCVE-2020-26217: XStream <1.4.14 - Remote Code ExecutionPoCCVE-2020-26258: XStream <1.4.15 - Server-Side Request ForgeryPoCCVE-2021-21345: XStream < 1.4.16 - Remote Code ExecutionPoCCVE-2021-21351: XStream <1.4.16 - Remote Code ExecutionPoCCVE-2021-29505: XStream <1.4.17 - Remote Code ExecutionPoCCVE-2021-39141: XStream 1.4.18 - Remote Code ExecutionPoCCVE-2021-39144: XStream 1.4.18 - Remote Code ExecutionPoCCVE-2021-39146: XStream 1.4.18 - Arbitrary Code ExecutionPoCCVE-2021-39152: XStream <1.4.18 - Server-Side Request ForgeryPoCvmware-nsx-stream-rce: VMware NSX Manager XStream Pre-authenticated Remote Code ExecutionEasySite Xstream 反序列化漏洞Xstream Project Xstream 栈溢出漏洞 可致拒绝服务