VDB
RHSA-2021:0105
RHSA-2021:0105
PUBLISHED
CVSS 9 CRITICAL
A flaw was found in xstream. An unsafe deserialization of user-supplied XML, in conjunction with relying on the default deny list, allows a remote attacker to perform a variety of attacks including a remote code execution of arbitrary code in the context of the JVM running the XStream application. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Risk Scores
CVSS 3.1
9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | RHPAM 7.9.1 |
Timeline
- Jan 13, 2021 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
- May 15, 2026 Distribution Patch
- May 15, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2021:0105 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1898907 issue
- https://www.cve.org/CVERecord?id=CVE-2020-26217 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_0105.json advisory
- https://access.redhat.com/security/cve/CVE-2020-26217 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-26217 advisory