{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "Server-side request forgery (SSRF) via unsafe deserialization of com.sun.xml.internal.ws.client.sei.*",
    "tracking": {
      "current_release_date": "2026-08-11T15:00:28+00:00",
      "generator": {
        "date": "2026-08-11T15:00:28+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2021-39150",
      "initial_release_date": "2021-08-22T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T15:00:28+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.12",
            "product": {
              "name": "OpenShift Container Platform 4.12",
              "product_id": "openshift-4.12.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.12"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.13",
            "product": {
              "name": "OpenShift Container Platform 4.13",
              "product_id": "openshift-4.13.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.13"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.14",
            "product": {
              "name": "OpenShift Container Platform 4.14",
              "product_id": "openshift-4.14.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.14"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.15.z",
            "product": {
              "name": "OpenShift Container Platform 4.15.z",
              "product_id": "openshift-4.15.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.15"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.16.z",
            "product": {
              "name": "OpenShift Container Platform 4.16.z",
              "product_id": "openshift-4.16.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.16"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.17",
            "product": {
              "name": "OpenShift Container Platform 4.17",
              "product_id": "openshift-4.17",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.17"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.18",
            "product": {
              "name": "OpenShift Container Platform 4.18",
              "product_id": "openshift-4.18",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.18"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.19",
            "product": {
              "name": "OpenShift Container Platform 4.19",
              "product_id": "openshift-4.19",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.19"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 4.20",
            "product": {
              "name": "OpenShift Container Platform 4.20",
              "product_id": "openshift-4.20",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:4.20"
              }
            }
          },
          {
            "category": "product_name",
            "name": "OpenShift Container Platform 3.11.0",
            "product": {
              "name": "OpenShift Container Platform 3.11.0",
              "product_id": "openshift-enterprise-3.11",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openshift:3"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::client",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::client"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::computenode",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::computenode"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::server",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::server"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7.9.z",
            "product": {
              "name": "Red Hat Enterprise Linux 7.9.z",
              "product_id": "rhel-7.9.z::workstation",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:enterprise_linux:7::workstation"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jenkins",
            "product": {
              "name": "jenkins",
              "product_id": "jenkins",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins"
              }
            }
          },
          {
            "category": "product_version",
            "name": "jenkins",
            "product": {
              "name": "jenkins",
              "product_id": "jenkins.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/jenkins?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream",
            "product": {
              "name": "xstream",
              "product_id": "xstream-0:1.3.1-16.el7_9",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream@1.3.1-16.el7_9?epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream",
            "product": {
              "name": "xstream",
              "product_id": "xstream-0:1.3.1-16.el7_9.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream@1.3.1-16.el7_9?arch=src&epoch=0"
              }
            }
          },
          {
            "category": "product_version",
            "name": "xstream-javadoc",
            "product": {
              "name": "xstream-javadoc",
              "product_id": "xstream-javadoc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/xstream-javadoc"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:jenkins"
        },
        "product_reference": "jenkins",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.14",
          "product_id": "openshift-4.14.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.14.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 3.11.0",
          "product_id": "openshift-enterprise-3.11:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-enterprise-3.11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.15.z",
          "product_id": "openshift-4.15.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.15.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.17",
          "product_id": "openshift-4.17:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.17"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.20",
          "product_id": "openshift-4.20:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.12",
          "product_id": "openshift-4.12.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.12.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.18",
          "product_id": "openshift-4.18:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.13",
          "product_id": "openshift-4.13.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.13.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.16.z",
          "product_id": "openshift-4.16.z:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.16.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "jenkins.src as a component of OpenShift Container Platform 4.19",
          "product_id": "openshift-4.19:jenkins.src"
        },
        "product_reference": "jenkins.src",
        "relates_to_product_reference": "openshift-4.19"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9 as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9",
        "relates_to_product_reference": "rhel-7.9.z::server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9.src"
        },
        "product_reference": "xstream-0:1.3.1-16.el7_9.src",
        "relates_to_product_reference": "rhel-7.9.z::server"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::workstation:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::workstation"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::client:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::client"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::computenode:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::computenode"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "xstream-javadoc as a component of Red Hat Enterprise Linux 7.9.z",
          "product_id": "rhel-7.9.z::server:xstream-javadoc"
        },
        "product_reference": "xstream-javadoc",
        "relates_to_product_reference": "rhel-7.9.z::server"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-39150",
      "cwe": {
        "id": "CWE-918",
        "name": "Server-Side Request Forgery (SSRF)"
      },
      "discovery_date": "2021-08-23T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Users who follow the recommended security framework with a whitelist to limit the types to the minimum required should not be affected. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.\n\nOpenShift Container Platform (OCP) delivers the Jenkins LTS package with bundled XStream library. Due to JEP-200 [1] and JEP-228 [2] Jenkins projects, the OCP Jenkins package is not affected by this flaw.\nThis version of the XStream library will be delivered in future Jenkins releases.\n\n[1] https://github.com/jenkinsci/jep/blob/master/jep/200/README.adoc\n[2] https://github.com/jenkinsci/jep/blob/master/jep/228/README.adoc#security",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A flaw was found in xstream, a simple library used to serialize objects to XML and back again. This flaw allows a remote attacker to request data from internal resources that are not publicly available by manipulating the processed input stream with Java runtime versions 14 to 8. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9",
          "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9.src",
          "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9",
          "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9.src",
          "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9",
          "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9.src",
          "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9",
          "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9.src"
        ],
        "known_not_affected": [
          "openshift-4.12.z:jenkins.src",
          "openshift-4.13.z:jenkins.src",
          "openshift-4.14.z:jenkins.src",
          "openshift-4.15.z:jenkins.src",
          "openshift-4.16.z:jenkins.src",
          "openshift-4.17:jenkins.src",
          "openshift-4.18:jenkins.src",
          "openshift-4.19:jenkins.src",
          "openshift-4.20:jenkins.src",
          "openshift-enterprise-3.11:jenkins",
          "openshift-enterprise-3.11:jenkins.src",
          "rhel-7.9.z::client:xstream-javadoc",
          "rhel-7.9.z::computenode:xstream-javadoc",
          "rhel-7.9.z::server:xstream-javadoc",
          "rhel-7.9.z::workstation:xstream-javadoc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-39150"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-39150"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-39150"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2021-10-25T06:54:35+00:00",
          "details": "Apply advisory RHSA-2021:3956 as per vendors instructions.",
          "product_ids": [
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9.src"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2021:3956"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "baseScore": 8.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "openshift-4.12.z:jenkins.src",
            "openshift-4.13.z:jenkins.src",
            "openshift-4.14.z:jenkins.src",
            "openshift-4.15.z:jenkins.src",
            "openshift-4.16.z:jenkins.src",
            "openshift-4.17:jenkins.src",
            "openshift-4.18:jenkins.src",
            "openshift-4.19:jenkins.src",
            "openshift-4.20:jenkins.src",
            "openshift-enterprise-3.11:jenkins",
            "openshift-enterprise-3.11:jenkins.src",
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::client:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::client:xstream-javadoc",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::computenode:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::computenode:xstream-javadoc",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::server:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::server:xstream-javadoc",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9",
            "rhel-7.9.z::workstation:xstream-0:1.3.1-16.el7_9.src",
            "rhel-7.9.z::workstation:xstream-javadoc"
          ]
        }
      ],
      "title": "Server-side request forgery (SSRF) via unsafe deserialization of com.sun.xml.internal.ws.client.sei.*"
    }
  ]
}