{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry",
    "tracking": {
      "current_release_date": "2026-07-24T20:43:13+00:00",
      "generator": {
        "date": "2026-07-24T20:43:13+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2021-21345",
      "initial_release_date": "2021-03-12T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-24T20:43:13+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.12",
            "product": {
              "name": "OpenShift Container Platform 4.12",
              "product_id": "openshift-4.12.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.12"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.13",
            "product": {
              "name": "OpenShift Container Platform 4.13",
              "product_id": "openshift-4.13.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.13"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.14",
            "product": {
              "name": "OpenShift Container Platform 4.14",
              "product_id": "openshift-4.14.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.14"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.15.z",
            "product": {
              "name": "OpenShift Container Platform 4.15.z",
              "product_id": "openshift-4.15.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.15"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.16.z",
            "product": {
              "name": "OpenShift Container Platform 4.16.z",
              "product_id": "openshift-4.16.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.16"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.17",
            "product": {
              "name": "OpenShift Container Platform 4.17",
              "product_id": "openshift-4.17",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.17"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.18",
            "product": {
              "name": "OpenShift Container Platform 4.18",
              "product_id": "openshift-4.18",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.18"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.19",
            "product": {
              "name": "OpenShift Container Platform 4.19",
              "product_id": "openshift-4.19",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.19"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.20",
            "product": {
              "name": "OpenShift Container Platform 4.20",
              "product_id": "openshift-4.20",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.20"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 3.11.0",
            "product": {
              "name": "OpenShift Container Platform 3.11.0",
              "product_id": "openshift-enterprise-3.11",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:3"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::client",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::client"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::computenode",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::computenode"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::server",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::server"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::workstation",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::workstation"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jenkins",
            "product": {
              "name": "jenkins",
              "product_id": "jenkins.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream",
            "product": {
              "name": "xstream",
              "product_id": "xstream-0:1.3.1-13.el7_9",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream@1.3.1-13.el7_9?epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream",
            "product": {
              "name": "xstream",
              "product_id": "xstream-0:1.3.1-13.el7_9.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream@1.3.1-13.el7_9?arch=src&epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream-javadoc",
            "product": {
              "name": "xstream-javadoc",
              "product_id": "xstream-javadoc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream-javadoc"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.18",
          "product_id": "openshift-4.18:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.13",
          "product_id": "openshift-4.13.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.13.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.15.z",
          "product_id": "openshift-4.15.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.15.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.14",
          "product_id": "openshift-4.14.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.14.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.19",
          "product_id": "openshift-4.19:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.19"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.16.z",
          "product_id": "openshift-4.16.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.16.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.20",
          "product_id": "openshift-4.20:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.12",
          "product_id": "openshift-4.12.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.12.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.17",
          "product_id": "openshift-4.17:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.17"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-13.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-13.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-21345",
      "cwe": {
        "id": "CWE-502",
        "name": "Deserialization of Untrusted Data"
      },
      "discovery_date": "2021-03-23T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "OpenShift Container Platform (OCP) delivers Jenkins LTS package with bundled XStream library. Due to JEP-200 [1] and JEP-228 [2] Jenkins projects, OCP Jenkins package is not affected by this flaw.\n\n[1] https://github.com/jenkinsci/jep/blob/master/jep/200/README.adoc\n[2] https://github.com/jenkinsci/jep/blob/master/jep/228/README.adoc#security",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in xstream. A remote attacker, who has sufficient rights, can execute commands of the host by manipulating the processed input stream. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9",
          "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9.src",
          "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9",
          "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9.src",
          "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9",
          "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9.src",
          "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9",
          "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9.src"
        ],
        "known_not_affected": [
          "openshift-4.12.z:jenkins.src",
          "openshift-4.13.z:jenkins.src",
          "openshift-4.14.z:jenkins.src",
          "openshift-4.15.z:jenkins.src",
          "openshift-4.16.z:jenkins.src",
          "openshift-4.17:jenkins.src",
          "openshift-4.18:jenkins.src",
          "openshift-4.19:jenkins.src",
          "openshift-4.20:jenkins.src",
          "openshift-enterprise-3.11:jenkins.src",
          "rhel-7.9.z::client:xstream-javadoc",
          "rhel-7.9.z::computenode:xstream-javadoc",
          "rhel-7.9.z::server:xstream-javadoc",
          "rhel-7.9.z::workstation:xstream-javadoc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-21345"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21345"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-21345"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2021-04-26T05:52:30+00:00",
          "details": "Apply advisory RHSA-2021:1354 as per vendors instructions.",
          "product_ids": [
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9.src"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:1354"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "baseScore": 8.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-13.el7_9.src",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "title": "Unsafe deserizaliation of com.sun.corba.se.impl.activation.ServerTableEntry"
    }
  ]
}