CVE-2020-26217High· 8.0▾ MidnightPoC availableXStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are aff…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44 · likelihood 17 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
85%
6 GitHub repos · Nuclei ×1 (last check)
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
xstream < 1.4.14debian_linux = 9.0debian_linux = 10.0snapmanageractivemq < 5.15.14activemq = 5.16.0banking_cash_management = 14.2banking_cash_management = 14.3banking_cash_management = 14.5banking_corporate_lending_process_management = 14.2banking_corporate_lending_process_management = 14.3banking_corporate_lending_process_management = 14.5banking_credit_facilities_process_management = 14.2banking_credit_facilities_process_management = 14.3banking_credit_facilities_process_management = 14.5banking_platform = 2.4.0banking_platform = 2.7.1banking_platform = 2.9.0banking_supply_chain_finance = 14.2banking_supply_chain_finance = 14.3banking_supply_chain_finance = 14.5banking_trade_finance_process_management = 14.2banking_trade_finance_process_management = 14.3banking_trade_finance_process_management = 14.5banking_virtual_account_management = 14.2.0banking_virtual_account_management = 14.3.0banking_virtual_account_management = 14.5.0business_activity_monitoring = 11.1.1.9.0business_activity_monitoring = 12.2.1.3.0business_activity_monitoring = 12.2.1.4.0communications_policy_management = 12.5.0endeca_information_discovery_studio = 3.2.0.0retail_xstore_point_of_service = 16.0.6retail_xstore_point_of_service = 17.0.4retail_xstore_point_of_service = 18.0.3retail_xstore_point_of_service = 19.0.2Upgrade past the affected range:
xstream 1.4.14activemq 5.15.14Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29505High· 7.5XStream is vulnerable to a Remote Command Execution attack
CVE-2021-39154High· 8.5XStream is a simple library to serialize objects to XML and back again
CVE-2021-39145High· 8.5XStream is a simple library to serialize objects to XML and back again
CVE-2021-39149High· 8.5XStream is a simple library to serialize objects to XML and back again
CVE-2021-39152High· 8.5A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
CVE-2021-39146High· 8.5XStream is vulnerable to an Arbitrary Code Execution attack