'; } else{ echo ''; } echo '
|
|||
Release Date:2025/9/15
Rule Name:CVE-2020-26217: XStream Command Injection Vulnerability
Severity:critical
CVE ID:CVE-2020-26217
Descripiton:
|
XStream is a lightweight, easy-to-use open source Java class library of the XStream (XStream) team, which is mainly used to sequence the object serial into XML (JSON) or reverse sequences. XStream 1.4.14 The previous version of the operating system command is injected into the vulnerability, which is from an attack that is easily executed by the remote code. Attackers can use this vulnerability to run any shell command only by manipulating the processed input stream. Only users who rely on black list will be affected. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
Solution:
|
Update vendor patches.