ZeroHour

CVE-2020-26217

PoC
CVSS 3.1
8.8 high
EPSS
85%p100
Published
()
Modified
Description

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Vendors
xstreamdebiannetappapacheoracle
Products
xstream, debian linux, snapmanager, activemq, banking cash management, banking corporate lending process management, banking credit facilities process management, banking platform, banking supply chain finance, banking trade finance process management, banking virtual account management, business activity monitoring
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.