{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "misinterpretation of malicious XML input",
    "tracking": {
      "current_release_date": "2026-08-11T15:08:05+00:00",
      "generator": {
        "date": "2026-08-11T15:08:05+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-32796",
      "initial_release_date": "2021-07-27T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T15:08:05+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.11.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.11.0",
              "product_id": "rhacm-2.11.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2.11"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.12.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.12.0",
              "product_id": "rhacm-2.12.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2.12"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.13.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.13.0",
              "product_id": "rhacm-2.13.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2.13"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.14.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.14.0",
              "product_id": "rhacm-2.14",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2.14"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.15.0",
            "product": {
              "name": "Red Hat Advanced Cluster Management for Kubernetes ACM 2.15.0",
              "product_id": "rhacm-2.15",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:acm:2.15"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rhacm2/console-ui-rhel8",
            "product": {
              "name": "rhacm2/console-ui-rhel8",
              "product_id": "rhacm2/console-ui-rhel8",
              "product_identification_helper": {
                "purl": "pkg:oci/console-ui-rhel8?repository_url=registry.redhat.io/rhacm2/console-ui-rhel8"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/console-ui-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.13.0",
          "product_id": "rhacm-2.13.z:rhacm2/console-ui-rhel8"
        },
        "product_reference": "rhacm2/console-ui-rhel8",
        "relates_to_product_reference": "rhacm-2.13.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/console-ui-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.12.0",
          "product_id": "rhacm-2.12.z:rhacm2/console-ui-rhel8"
        },
        "product_reference": "rhacm2/console-ui-rhel8",
        "relates_to_product_reference": "rhacm-2.12.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/console-ui-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.11.0",
          "product_id": "rhacm-2.11.z:rhacm2/console-ui-rhel8"
        },
        "product_reference": "rhacm2/console-ui-rhel8",
        "relates_to_product_reference": "rhacm-2.11.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/console-ui-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.14.0",
          "product_id": "rhacm-2.14:rhacm2/console-ui-rhel8"
        },
        "product_reference": "rhacm2/console-ui-rhel8",
        "relates_to_product_reference": "rhacm-2.14"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rhacm2/console-ui-rhel8 as a component of Red Hat Advanced Cluster Management for Kubernetes ACM 2.15.0",
          "product_id": "rhacm-2.15:rhacm2/console-ui-rhel8"
        },
        "product_reference": "rhacm2/console-ui-rhel8",
        "relates_to_product_reference": "rhacm-2.15"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-32796",
      "cwe": {
        "id": "CWE-20",
        "name": "Improper Input Validation"
      },
      "discovery_date": "2021-07-27T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhacm-2.11.z:rhacm2/console-ui-rhel8",
            "rhacm-2.12.z:rhacm2/console-ui-rhel8",
            "rhacm-2.13.z:rhacm2/console-ui-rhel8",
            "rhacm-2.14:rhacm2/console-ui-rhel8",
            "rhacm-2.15:rhacm2/console-ui-rhel8"
          ]
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in nodejs-xmldom. The xmldom library is an open-source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Xmldom does not correctly escape special characters when serializing elements removed from their ancestor. This flaw may lead to unexpected syntactic changes during XML processing in some downstream applications. Invalid processing of XML documents could lead to a loss of confidentiality or integrity of data in the application using the vulnerable library.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhacm-2.11.z:rhacm2/console-ui-rhel8",
          "rhacm-2.12.z:rhacm2/console-ui-rhel8",
          "rhacm-2.13.z:rhacm2/console-ui-rhel8",
          "rhacm-2.14:rhacm2/console-ui-rhel8",
          "rhacm-2.15:rhacm2/console-ui-rhel8"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-32796"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32796"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-32796"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM"
          },
          "products": [
            "rhacm-2.11.z:rhacm2/console-ui-rhel8",
            "rhacm-2.12.z:rhacm2/console-ui-rhel8",
            "rhacm-2.13.z:rhacm2/console-ui-rhel8",
            "rhacm-2.14:rhacm2/console-ui-rhel8",
            "rhacm-2.15:rhacm2/console-ui-rhel8"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhacm-2.11.z:rhacm2/console-ui-rhel8",
            "rhacm-2.12.z:rhacm2/console-ui-rhel8",
            "rhacm-2.13.z:rhacm2/console-ui-rhel8",
            "rhacm-2.14:rhacm2/console-ui-rhel8",
            "rhacm-2.15:rhacm2/console-ui-rhel8"
          ]
        }
      ],
      "title": "misinterpretation of malicious XML input"
    }
  ]
}