VDB

DEBIAN-CVE-2020-26217

DEBIAN-CVE-2020-26217 PUBLISHED CVSS 8.800000190734863 HIGH

XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11libxstream-java0, 0, 0
Debian:14libxstream-java0, 0, 0
Debian:12libxstream-java0, 0, 0
Debian:13libxstream-java0, 0, 0

Timeline

  • Nov 16, 2020 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›