CVE-2020-26217

EUVD-2020-1464
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
GitHub_MCNA
8 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
xstreamxstream
𝑥
< 1.4.14
debiandebian_linux
9.0
debiandebian_linux
10.0
netappsnapmanager
*
netappsnapmanager
-
apacheactivemq
𝑥
< 5.15.14
apacheactivemq
5.16.0
oraclebanking_cash_management
14.2
oraclebanking_cash_management
14.3
oraclebanking_cash_management
14.5
oraclebanking_corporate_lending_process_management
14.2
oraclebanking_corporate_lending_process_management
14.3
oraclebanking_corporate_lending_process_management
14.5
oraclebanking_credit_facilities_process_management
14.2
oraclebanking_credit_facilities_process_management
14.3
oraclebanking_credit_facilities_process_management
14.5
oraclebanking_platform
2.4.0
oraclebanking_platform
2.7.1
oraclebanking_platform
2.9.0
oraclebanking_supply_chain_finance
14.2
oraclebanking_supply_chain_finance
14.3
oraclebanking_supply_chain_finance
14.5
oraclebanking_trade_finance_process_management
14.2
oraclebanking_trade_finance_process_management
14.3
oraclebanking_trade_finance_process_management
14.5
oraclebanking_virtual_account_management
14.2.0
oraclebanking_virtual_account_management
14.3.0
oraclebanking_virtual_account_management
14.5.0
oraclebusiness_activity_monitoring
11.1.1.9.0
oraclebusiness_activity_monitoring
12.2.1.3.0
oraclebusiness_activity_monitoring
12.2.1.4.0
oraclecommunications_policy_management
12.5.0
oracleendeca_information_discovery_studio
3.2.0.0
oracleretail_xstore_point_of_service
16.0.6
oracleretail_xstore_point_of_service
17.0.4
oracleretail_xstore_point_of_service
18.0.3
oracleretail_xstore_point_of_service
19.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libxstream-java
bookworm
1.4.20-1
fixed
bullseye
1.4.15-3+deb11u2
fixed
bullseye (security)
1.4.15-3+deb11u2
fixed
sid
1.4.20-2
fixed
trixie
1.4.20-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libxstream-java
bionic
Fixed 1.4.11.1-1~18.04.1
released
focal
Fixed 1.4.11.1-1ubuntu0.1
released
groovy
Fixed 1.4.11.1-2ubuntu0.1
released
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
Fixed 1.4.7-1ubuntu0.1+esm2
released
xenial
Fixed 1.4.8-1ubuntu0.1+esm3
released
References