Input validation error in xstream - CVE-2020-26259
Published: December 16, 2020 / Updated: December 17, 2024
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary files on the system.
The vulnerability exists due to insufficient validation of user-supplied input within the blacklisting feature. A remote attacker can pass specially crafted input to the application and delete arbitrary files on the system.
Affected software
libxstream-java (Debian package)
libxstream-java (Ubuntu package)
prometheus-formula
grafana-formula
prometheus-exporters-formula
subscription-matcher
xpp3-minimal
xpp3
xstream-javadoc
xstream-parent
xstream-benchmark
xstream-hibernate
xstream
smdba
cobbler
python3-rhnlib
spacewalk-proxy-salt
spacewalk-proxy-redirect
spacewalk-proxy-package-manager
spacewalk-proxy-management
spacewalk-proxy-common
spacewalk-proxy-broker
python3-mgr-osa-common
python3-mgr-osa-dispatcher
mgr-osa-dispatcher
python3-mgr-osad
mgr-osad
spacewalk-config
spacewalk-proxy-installer
mgr-libmod
spacewalk-client-tools
python3-spacewalk-check
python3-spacewalk-client-tools
python3-spacewalk-client-setup
spacewalk-check
spacewalk-client-setup
susemanager-docs_en
susemanager-docs_en-pdf
susemanager-doc-indexes
spacewalk-utils
spacewalk-utils-extras
susemanager-schema
uyuni-config-modules
susemanager-sls
spacewalk-backend-config-files
spacewalk-backend
spacewalk-backend-app
spacewalk-backend-applet
spacewalk-backend-config-files-common
spacewalk-backend-config-files-tool
spacewalk-backend-iss
spacewalk-backend-xmlrpc
spacewalk-backend-xml-export-libs
spacewalk-backend-tools
spacewalk-backend-sql-postgresql
spacewalk-backend-sql
spacewalk-backend-server
spacewalk-backend-package-push-server
spacewalk-backend-iss-export
susemanager-web-libs
spacewalk-base
spacewalk-base-minimal
spacewalk-base-minimal-config
spacewalk-html
susemanager-tools
susemanager
spacewalk-java
spacewalk-taskomatic
spacewalk-java-postgresql
spacewalk-java-lib
spacewalk-java-config
py26-compat-salt
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Proxy
Ubuntu
openEuler
Fedora
IBM Rational Quality Manager
Engineering Test Management
Storage Copy Data Management
Red Hat Decision Manager
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Security Verify Governance
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Fuse
How to mitigate CVE-2020-26259
libxstream-java (Debian package) - update to 1.4.11.1-1+deb10u2
Red Hat Decision Manager - update to 7.11.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.11.0
libxstream-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.4.11.1-1ubuntu0.1, 1.4.11.1-1ubuntu0.2, 1.4.11.1-1~18.04.1, 1.4.11.1-1~18.04.2, 1.4.11.1-2ubuntu0.1, 1.4.15-1ubuntu0.1
prometheus-formula - update to 0.3.1-3.6.2
grafana-formula - update to 0.4.0-3.6.2
prometheus-exporters-formula - update to 0.9.0-3.19.2
subscription-matcher - update to 0.26-3.6.2
xpp3-minimal - update to 1.1.4c-11.2.2
xpp3 - update to 1.1.4c-11.2.2
xstream-javadoc - update to 1.4.11.1-3
xstream-parent - update to 1.4.11.1-3
xstream-benchmark - update to 1.4.11.1-3
xstream-hibernate - update to 1.4.11.1-3
xstream - update to 1.4.11.1-3
xstream - update to 1.4.15-3.5.2
xstream - addressed in versions 1.4.18-2.fc33, 1.4.18-2.fc34, 1.4.18-2.fc35
smdba - update to 1.7.8-0.3.6.2
Storage Copy Data Management - update to 2.2.26.0
cobbler - update to 3.0.0+git20190806.32c4bae0-5.6.4
python3-rhnlib - update to 4.1.3-4.3.2
spacewalk-proxy-salt - update to 4.1.4-3.9.4
spacewalk-proxy-redirect - update to 4.1.4-3.9.4
spacewalk-proxy-package-manager - update to 4.1.4-3.9.4
spacewalk-proxy-management - update to 4.1.4-3.9.4
spacewalk-proxy-common - update to 4.1.4-3.9.4
spacewalk-proxy-broker - update to 4.1.4-3.9.4
python3-mgr-osa-common - update to 4.1.5-2.9.4
python3-mgr-osa-dispatcher - update to 4.1.5-2.9.4
mgr-osa-dispatcher - update to 4.1.5-2.9.4
python3-mgr-osad - update to 4.1.5-2.9.4
mgr-osad - update to 4.1.5-2.9.4
spacewalk-config - update to 4.1.5-3.3.2
spacewalk-proxy-installer - update to 4.1.6-3.3.2
mgr-libmod - update to 4.1.7-3.16.2
spacewalk-client-tools - update to 4.1.9-4.12.4
python3-spacewalk-check - update to 4.1.9-4.12.4
python3-spacewalk-client-tools - update to 4.1.9-4.12.4
python3-spacewalk-client-setup - update to 4.1.9-4.12.4
spacewalk-check - update to 4.1.9-4.12.4
spacewalk-client-setup - update to 4.1.9-4.12.4
susemanager-docs_en - update to 4.1-11.28.2
susemanager-docs_en-pdf - update to 4.1-11.28.2
susemanager-doc-indexes - update to 4.1-11.28.4
spacewalk-utils - update to 4.1.14-3.12.2
spacewalk-utils-extras - update to 4.1.14-3.12.2
susemanager-schema - update to 4.1.19-3.24.4
uyuni-config-modules - update to 4.1.21-3.26.2
susemanager-sls - update to 4.1.21-3.26.2
spacewalk-backend-config-files - update to 4.1.21-4.22.7
spacewalk-backend - update to 4.1.21-4.22.7
spacewalk-backend-app - update to 4.1.21-4.22.7
spacewalk-backend-applet - update to 4.1.21-4.22.7
spacewalk-backend-config-files-common - update to 4.1.21-4.22.7
spacewalk-backend-config-files-tool - update to 4.1.21-4.22.7
spacewalk-backend-iss - update to 4.1.21-4.22.7
spacewalk-backend-xmlrpc - update to 4.1.21-4.22.7
spacewalk-backend-xml-export-libs - update to 4.1.21-4.22.7
spacewalk-backend-tools - update to 4.1.21-4.22.7
spacewalk-backend-sql-postgresql - update to 4.1.21-4.22.7
spacewalk-backend-sql - update to 4.1.21-4.22.7
spacewalk-backend-server - update to 4.1.21-4.22.7
spacewalk-backend-package-push-server - update to 4.1.21-4.22.7
spacewalk-backend-iss-export - update to 4.1.21-4.22.7
susemanager-web-libs - update to 4.1.23-3.18.6
spacewalk-base - update to 4.1.23-3.18.6
spacewalk-base-minimal - update to 4.1.23-3.18.6
spacewalk-base-minimal-config - update to 4.1.23-3.18.6
spacewalk-html - update to 4.1.23-3.18.6
susemanager-tools - update to 4.1.24-3.20.2
susemanager - update to 4.1.24-3.20.2
spacewalk-java - update to 4.1.30-3.31.7
spacewalk-taskomatic - update to 4.1.30-3.31.7
spacewalk-java-postgresql - update to 4.1.30-3.31.7
spacewalk-java-lib - update to 4.1.30-3.31.7
spacewalk-java-config - update to 4.1.30-3.31.7
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0
Fuse - update to 7.10.0
IBM Security Verify Governance - update to 10.0.1.0.2
py26-compat-salt - update to 2016.11.10-6.11.2
Links to Public Exploits and PoC-codes
- Exploit #5062 - CVE-2020-26259 (CVE-2020-26259 &&XStream Arbitrary File Delete) (January 24, 2021)
- Exploit #4943 - CVE-2020-26259 (CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights.) (December 16, 2020)
External References
Related Security Bulletins
- Multiple vulnerabilities in XStream
- Debian update for libxstream-java
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Decision Manager
- Ubuntu update for libxstream-java
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in IBM Engineering Test Management and IBM Rational Quality Manager
- SUSE update for SUSE Manager Server 4.1
- Multiple vulnerabilities in IBM Security Verify Governance
- openEuler 20.03 LTS SP1 update for xstream
- Ubuntu update for libxstream-java
- Multiple vulnerabilities in Fuse 7.10
- Fedora 35 update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 33 update for xstream
- Fedora 34 update for xstream
- Fedora 35 update for xstream
- Multiple vulnerabilities in IBM Watson Discovery
- Multiple vulnerabilities in IBM Storage Copy Data Management