OS Command Injection in xstream - CVE-2020-26217
Published: November 16, 2020 / Updated: January 24, 2021
Vulnerability details
The vulnerability allows a remote user to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation, when processing blacklists. A remote user can pass specially crafted data to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
xstream (Red Hat package)
libxstream-java (Debian package)
libxstream-java (Ubuntu package)
prometheus-formula
grafana-formula
prometheus-exporters-formula
subscription-matcher
xpp3
xpp3-minimal
xstream
smdba
cobbler
python3-rhnlib
spacewalk-proxy-common
spacewalk-proxy-broker
spacewalk-proxy-management
spacewalk-proxy-package-manager
spacewalk-proxy-redirect
spacewalk-proxy-salt
python3-mgr-osa-dispatcher
python3-mgr-osad
mgr-osad
mgr-osa-dispatcher
python3-mgr-osa-common
spacewalk-config
spacewalk-proxy-installer
mgr-libmod
python3-spacewalk-client-tools
spacewalk-client-setup
spacewalk-check
python3-spacewalk-client-setup
python3-spacewalk-check
spacewalk-client-tools
susemanager-docs_en-pdf
susemanager-docs_en
susemanager-doc-indexes
spacewalk-utils
spacewalk-utils-extras
susemanager-schema
uyuni-config-modules
susemanager-sls
spacewalk-backend-applet
spacewalk-backend-config-files
spacewalk-backend-app
spacewalk-backend-config-files-common
spacewalk-backend
spacewalk-backend-tools
spacewalk-backend-config-files-tool
spacewalk-backend-iss
spacewalk-backend-iss-export
spacewalk-backend-package-push-server
spacewalk-backend-server
spacewalk-backend-sql
spacewalk-backend-xmlrpc
spacewalk-backend-xml-export-libs
spacewalk-backend-sql-postgresql
susemanager-web-libs
spacewalk-html
spacewalk-base-minimal-config
spacewalk-base-minimal
spacewalk-base
susemanager-tools
susemanager
spacewalk-taskomatic
spacewalk-java-postgresql
spacewalk-java-lib
spacewalk-java-config
spacewalk-java
py26-compat-salt
Oracle Banking Platform
Storage Copy Data Management
Oracle Endeca Information Discovery Studio
Oracle Business Activity Monitoring
SUSE Linux Enterprise Module for SUSE Manager Proxy
SUSE Linux Enterprise Module for SUSE Manager Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Ubuntu
Bamboo Server
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
Fuse
How to mitigate CVE-2020-26217
xstream (Red Hat package) - update to 1.3.1-12.el7_9
libxstream-java (Debian package) - update to 1.4.11.1-1+deb10u1
Bamboo Server - update to 9.2.8
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.1, 1.4.11.1-1ubuntu0.2, 1.4.11.1-1~18.04.1, 1.4.11.1-1~18.04.2, 1.4.11.1-2ubuntu0.1, 1.4.15-1ubuntu0.1
prometheus-formula - update to 0.3.1-3.6.2
grafana-formula - update to 0.4.0-3.6.2
prometheus-exporters-formula - update to 0.9.0-3.19.2
subscription-matcher - update to 0.26-3.6.2
xpp3 - update to 1.1.4c-11.2.2
xpp3-minimal - update to 1.1.4c-11.2.2
xstream - update to 1.4.15-3.5.2
smdba - update to 1.7.8-0.3.6.2
Storage Copy Data Management - update to 2.2.26.0
cobbler - update to 3.0.0+git20190806.32c4bae0-5.6.4
python3-rhnlib - update to 4.1.3-4.3.2
spacewalk-proxy-common - update to 4.1.4-3.9.4
spacewalk-proxy-broker - update to 4.1.4-3.9.4
spacewalk-proxy-management - update to 4.1.4-3.9.4
spacewalk-proxy-package-manager - update to 4.1.4-3.9.4
spacewalk-proxy-redirect - update to 4.1.4-3.9.4
spacewalk-proxy-salt - update to 4.1.4-3.9.4
python3-mgr-osa-dispatcher - update to 4.1.5-2.9.4
python3-mgr-osad - update to 4.1.5-2.9.4
mgr-osad - update to 4.1.5-2.9.4
mgr-osa-dispatcher - update to 4.1.5-2.9.4
python3-mgr-osa-common - update to 4.1.5-2.9.4
spacewalk-config - update to 4.1.5-3.3.2
spacewalk-proxy-installer - update to 4.1.6-3.3.2
mgr-libmod - update to 4.1.7-3.16.2
python3-spacewalk-client-tools - update to 4.1.9-4.12.4
spacewalk-client-setup - update to 4.1.9-4.12.4
spacewalk-check - update to 4.1.9-4.12.4
python3-spacewalk-client-setup - update to 4.1.9-4.12.4
python3-spacewalk-check - update to 4.1.9-4.12.4
spacewalk-client-tools - update to 4.1.9-4.12.4
susemanager-docs_en-pdf - update to 4.1-11.28.2
susemanager-docs_en - update to 4.1-11.28.2
susemanager-doc-indexes - update to 4.1-11.28.4
spacewalk-utils - update to 4.1.14-3.12.2
spacewalk-utils-extras - update to 4.1.14-3.12.2
susemanager-schema - update to 4.1.19-3.24.4
uyuni-config-modules - update to 4.1.21-3.26.2
susemanager-sls - update to 4.1.21-3.26.2
spacewalk-backend-applet - update to 4.1.21-4.22.7
spacewalk-backend-config-files - update to 4.1.21-4.22.7
spacewalk-backend-app - update to 4.1.21-4.22.7
spacewalk-backend-config-files-common - update to 4.1.21-4.22.7
spacewalk-backend - update to 4.1.21-4.22.7
spacewalk-backend-tools - update to 4.1.21-4.22.7
spacewalk-backend-config-files-tool - update to 4.1.21-4.22.7
spacewalk-backend-iss - update to 4.1.21-4.22.7
spacewalk-backend-iss-export - update to 4.1.21-4.22.7
spacewalk-backend-package-push-server - update to 4.1.21-4.22.7
spacewalk-backend-server - update to 4.1.21-4.22.7
spacewalk-backend-sql - update to 4.1.21-4.22.7
spacewalk-backend-xmlrpc - update to 4.1.21-4.22.7
spacewalk-backend-xml-export-libs - update to 4.1.21-4.22.7
spacewalk-backend-sql-postgresql - update to 4.1.21-4.22.7
susemanager-web-libs - update to 4.1.23-3.18.6
spacewalk-html - update to 4.1.23-3.18.6
spacewalk-base-minimal-config - update to 4.1.23-3.18.6
spacewalk-base-minimal - update to 4.1.23-3.18.6
spacewalk-base - update to 4.1.23-3.18.6
susemanager-tools - update to 4.1.24-3.20.2
susemanager - update to 4.1.24-3.20.2
spacewalk-taskomatic - update to 4.1.30-3.31.7
spacewalk-java-postgresql - update to 4.1.30-3.31.7
spacewalk-java-lib - update to 4.1.30-3.31.7
spacewalk-java-config - update to 4.1.30-3.31.7
spacewalk-java - update to 4.1.30-3.31.7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
Fuse - addressed in versions 6.3.0, 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.2
py26-compat-salt - update to 2016.11.10-6.11.2
Links to Public Exploits and PoC-codes
External References
- https://github.com/x-stream/xstream/commit/0fec095d534126931c99fd38e9c6d41f5c685c1a
- https://github.com/x-stream/xstream/security/advisories/GHSA-mw36-7c6c-q4q2
- https://lists.debian.org/debian-lts-announce/2020/12/msg00001.html
- https://www.debian.org/security/2020/dsa-4811
- https://x-stream.github.io/CVE-2020-26217.html
Related Security Bulletins
- OS command injection in XStream
- Debian update for libxstream-java
- Red Hat Enterprise Linux 7 update for xstream
- CentOS 7 update for xstream
- Multiple vulnerabilities in Oracle Banking Platform
- Multiple vulnerabilities in Oracle Endeca Information Discovery Studio
- OS Command Injection in Oracle BAM (Business Activity Monitoring)
- Ubuntu update for libxstream-java
- Ubuntu update for libxstream-java
- SUSE update for SUSE Manager Server 4.1
- Multiple vulnerabilities in IBM Security Verify Governance
- Bamboo Data Center and Server update for RCE in xstream
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in Fuse 6
- Multiple vulnerabilities in Fuse 7.10
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Storage Copy Data Management