V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2020-26217
DEB
CriticalConfirmedExploit available

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell c…

CVSS
9.0
Critical
EPSS
0.85
p99
Published
2020-01-01
Updated
2020-01-01
Description

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Tags · CWE
Pre-auth
CWE-502
CWE-78
CAPEC-6
CAPEC-15
CAPEC-43
CAPEC-88
CAPEC-108
CAPEC-586
Affected products
Activemq < 5.15.14Activemq
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2020-01-01
Published
2020-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.850 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2020-26217
github-poc · https://github.com/Kairo-one/CVE-2020-26217-XStream
Enterprise
Affected products
ProductVendorStatus
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
libxstream-javaTracked
xstreamTracked
xstreamTracked
xstream-benchmarkTracked
xstream-javadocTracked
xstream-parentTracked
activemq*Tracked
Showing first 20 of 34
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities