cbcvebase.
CVE-2020-26217
published 2020-11-16

CVE-2020-26217: XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EXPLOIT
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
apacheactivemq< 5.15.145.15.14
apacheactivemq
atlassianbamboo_data_center
debiandebian_linux
debiandebian_linux
debianlibxstream-java< libxstream-java 1.4.14-1 (bookworm)libxstream-java 1.4.14-1 (bookworm)
oraclebanking_cash_management
oraclebanking_cash_management
oraclebanking_cash_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_corporate_lending_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_credit_facilities_process_management
oraclebanking_platform
oraclebanking_platform
oraclebanking_platform
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_supply_chain_finance
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_trade_finance_process_management
oraclebanking_virtual_account_management

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL