XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workarounds for users who cannot upgrade. The issue is fixed in version 1.4.14.
Metrics
Affected Vendors & Products
References
History
Fri, 23 May 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xstream
Xstream xstream |
|
CPEs | cpe:2.3:a:xstream_project:xstream:*:*:*:*:*:*:*:* |
cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* cpe:2.3:a:apache:activemq:5.16.0:*:*:*:*:*:*:* cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:* |
Vendors & Products |
Xstream Project
Xstream Project xstream |
Xstream
Xstream xstream |

Status: PUBLISHED
Assigner: GitHub_M
Published: 2020-11-16T21:00:18
Updated: 2024-08-04T15:49:07.258Z
Reserved: 2020-10-01T00:00:00
Link: CVE-2020-26217

No data.

Status : Analyzed
Published: 2020-11-16T21:15:12.893
Modified: 2025-05-23T16:54:19.697
Link: CVE-2020-26217
