VDB
RHSA-2021%3A0106
RHSA-2021%3A0106
PUBLISHED
CVSS 9 CRITICAL
A flaw was found in xstream. An unsafe deserialization of user-supplied XML, in conjunction with relying on the default deny list, allows a remote attacker to perform a variety of attacks including a remote code execution of arbitrary code in the context of the JVM running the XStream application. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Scores
CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHDM 7.9.1 |
Timeline
- Jan 13, 2021 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2021:0106 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1898907 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0106.json advisory
- https://access.redhat.com/security/cve/CVE-2020-26217 advisory
- https://www.cve.org/CVERecord?id=CVE-2020-26217 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-26217 advisory