Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-26217

Опубликовано: 16 нояб. 2020
Источник: ubuntu
Приоритет: medium
CVSS2: 9.3
CVSS3: 8

Описание

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

РелизСтатусПримечание
bionic

released

1.4.11.1-1~18.04.1
devel

not-affected

1.4.14-1
esm-apps-legacy/xenial

released

1.4.8-1ubuntu0.1+esm3
esm-apps/bionic

released

1.4.11.1-1~18.04.1
esm-apps/focal

released

1.4.11.1-1ubuntu0.1
esm-apps/jammy

not-affected

1.4.14-1
esm-apps/noble

not-affected

1.4.14-1
esm-apps/xenial

released

1.4.8-1ubuntu0.1+esm3
esm-infra-legacy/trusty

released

1.4.7-1ubuntu0.1+esm2
focal

released

1.4.11.1-1ubuntu0.1

Показывать по

9.3 Critical

CVSS2

8 High

CVSS3

Связанные уязвимости

CVSS3: 9
redhat
больше 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
nvd
больше 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
debian
больше 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...

CVSS3: 8
github
больше 5 лет назад

XStream can be used for Remote Code Execution

oracle-oval
больше 5 лет назад

ELSA-2021-0162: xstream security update (IMPORTANT)

9.3 Critical

CVSS2

8 High

CVSS3