CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
99.9%
Zhihong Tian and Hui Lu found that XStream was vulnerable to remote code
execution. A remote attacker could run arbitrary shell commands by
manipulating the processed input stream. This issue affected only affected
Ubuntu 20.10. (CVE-2020-26217)
It was discovered that XStream was vulnerable to server-side forgery attacks.
A remote attacker could request data from internal resources that are not
publicly available only by manipulating the processed input stream. This
issue only affected Ubuntu 20.10. (CVE-2020-26258)
It was discovered that XStream was vulnerable to arbitrary file deletion on
the local host. A remote attacker could use this to delete arbitrary known
files on the host as long as the executing process had sufficient rights only
by manipulating the processed input stream. This issue only affected
Ubuntu 20.10. (CVE-2020-26259)
It was discovered that XStream was vulnerable to denial of service,
arbitrary code execution, arbitrary file deletion and server-side forgery
attacks. A remote attacker could cause any of those issues by manipulating
the processed input stream. (CVE-2021-21341, CVE-2021-21342, CVE-2021-21343
CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347,
CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 21.04 | noarch | libxstream-java | < 1.4.15-1ubuntu0.1 | UNKNOWN |
Ubuntu | 20.10 | noarch | libxstream-java | < 1.4.11.1-2ubuntu0.1 | UNKNOWN |
Ubuntu | 20.04 | noarch | libxstream-java | < 1.4.11.1-1ubuntu0.2 | UNKNOWN |
Ubuntu | 18.04 | noarch | libxstream-java | < 1.4.11.1-1~18.04.2 | UNKNOWN |
ubuntu.com/security/CVE-2020-26217
ubuntu.com/security/CVE-2020-26258
ubuntu.com/security/CVE-2020-26259
ubuntu.com/security/CVE-2021-21341
ubuntu.com/security/CVE-2021-21342
ubuntu.com/security/CVE-2021-21343
ubuntu.com/security/CVE-2021-21344
ubuntu.com/security/CVE-2021-21345
ubuntu.com/security/CVE-2021-21346
ubuntu.com/security/CVE-2021-21347
ubuntu.com/security/CVE-2021-21348
ubuntu.com/security/CVE-2021-21349
ubuntu.com/security/CVE-2021-21350
ubuntu.com/security/CVE-2021-21351
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:M/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
99.9%