Логотип exploitDog
bind:CVE-2020-26217
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-26217

Количество 9

Количество 9

ubuntu логотип

CVE-2020-26217

около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
EPSS: Критический
redhat логотип

CVE-2020-26217

около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 9
EPSS: Критический
nvd логотип

CVE-2020-26217

около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
EPSS: Критический
debian логотип

CVE-2020-26217

около 5 лет назад

XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...

CVSS3: 8
EPSS: Критический
github логотип

GHSA-mw36-7c6c-q4q2

около 5 лет назад

XStream can be used for Remote Code Execution

CVSS3: 8
EPSS: Критический
oracle-oval логотип

ELSA-2021-0162

около 5 лет назад

ELSA-2021-0162: xstream security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-05622

около 5 лет назад

Уязвимость Java-библиотеки для преобразования объектов в XML или JSON формат Xstream, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2021:0140-1

около 5 лет назад

Security update for xstream

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2021:0176-1

около 5 лет назад

Security update for xstream

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
94%
Критический
около 5 лет назад
redhat логотип
CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 9
94%
Критический
около 5 лет назад
nvd логотип
CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

CVSS3: 8
94%
Критический
около 5 лет назад
debian логотип
CVE-2020-26217

XStream before version 1.4.14 is vulnerable to Remote Code Execution.T ...

CVSS3: 8
94%
Критический
около 5 лет назад
github логотип
GHSA-mw36-7c6c-q4q2

XStream can be used for Remote Code Execution

CVSS3: 8
94%
Критический
около 5 лет назад
oracle-oval логотип
ELSA-2021-0162

ELSA-2021-0162: xstream security update (IMPORTANT)

около 5 лет назад
fstec логотип
BDU:2020-05622

Уязвимость Java-библиотеки для преобразования объектов в XML или JSON формат Xstream, существующая из-за непринятия мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
94%
Критический
около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0140-1

Security update for xstream

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2021:0176-1

Security update for xstream

около 5 лет назад

Уязвимостей на страницу