XStream before 1.4.16 is susceptible to remote code execution. An attacker who has sufficient rights can execute host commands via manipulating the processed input stream, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations.
View the template here CVE-2021-21345.yaml
References:
https://x-stream.github.io/CVE-2021-21345.html