Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-26217

Опубликовано: 16 нояб. 2020
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 9.3
CVSS3: 8

Описание

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

РелизСтатусПримечание
bionic

released

1.4.11.1-1~18.04.1
devel

not-affected

1.4.14-1
esm-apps/bionic

released

1.4.11.1-1~18.04.1
esm-apps/focal

released

1.4.11.1-1ubuntu0.1
esm-apps/jammy

not-affected

1.4.14-1
esm-apps/noble

not-affected

1.4.14-1
esm-apps/xenial

released

1.4.8-1ubuntu0.1+esm3
esm-infra-legacy/trusty

released

1.4.7-1ubuntu0.1+esm2
focal

released

1.4.11.1-1ubuntu0.1
groovy

released

1.4.11.1-2ubuntu0.1

Показывать по

EPSS

Процентиль: 100%
0.93566
Критический

9.3 Critical

CVSS2

8 High

CVSS3

Связанные уязвимости

CVSS3: 9
redhat
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
nvd
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
debian
около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...

CVSS3: 8
github
около 5 лет назад

XStream can be used for Remote Code Execution

oracle-oval
около 5 лет назад

ELSA-2021-0162: xstream security update (IMPORTANT)

EPSS

Процентиль: 100%
0.93566
Критический

9.3 Critical

CVSS2

8 High

CVSS3