RedHat xstream CVE-2020-26217 Command Injection Vulnerability

description-logoDescription

XStream is a Java XML serialization library to serialize objects to and deserialize object from XML. Security Fix(es): XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

affected-products-logoAffected Applications

xstream

CVE References

CVE-2020-26217