CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
GitHub_MCNA
8 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
xstreamxstream
𝑥
< 1.4.14
debiandebian_linux
9.0
debiandebian_linux
10.0
netappsnapmanager
*
netappsnapmanager
-
apacheactivemq
𝑥
< 5.15.14
apacheactivemq
5.16.0
oraclebanking_cash_management
14.2
oraclebanking_cash_management
14.3
oraclebanking_cash_management
14.5
oraclebanking_corporate_lending_process_management
14.2
oraclebanking_corporate_lending_process_management
14.3
oraclebanking_corporate_lending_process_management
14.5
oraclebanking_credit_facilities_process_management
14.2
oraclebanking_credit_facilities_process_management
14.3
oraclebanking_credit_facilities_process_management
14.5
oraclebanking_platform
2.4.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.9.0
oraclebanking_supply_chain_finance
14.2
oraclebanking_supply_chain_finance
14.3
oraclebanking_supply_chain_finance
14.5
oraclebanking_trade_finance_process_management
14.2
oraclebanking_trade_finance_process_management
14.3
oraclebanking_trade_finance_process_management
14.5
oraclebanking_virtual_account_management
14.2.0
oraclebanking_virtual_account_management
14.3.0
oraclebanking_virtual_account_management
14.5.0
oraclebusiness_activity_monitoring
11.1.1.9.0
oraclebusiness_activity_monitoring
12.2.1.3.0
oraclebusiness_activity_monitoring
12.2.1.4.0
oraclecommunications_policy_management
12.5.0
oracleendeca_information_discovery_studio
3.2.0.0
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxstream-java
bullseye (security)
1.4.15-3+deb11u2
fixed
bullseye
1.4.15-3+deb11u2
fixed
bookworm
1.4.20-1
fixed
sid
1.4.20-2
fixed
trixie
1.4.20-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxstream-java
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
Fixed 1.4.11.1-2ubuntu0.1
released
focal
Fixed 1.4.11.1-1ubuntu0.1
released
bionic
Fixed 1.4.11.1-1~18.04.1
released
xenial
Fixed 1.4.8-1ubuntu0.1+esm3
released
trusty
Fixed 1.4.7-1ubuntu0.1+esm2
released
References