Red Hat Security Advisory: xstream security update
🔗 CVE IDs covered (14)
📋 Description
CVE-2021-39139 — xstream: Arbitrary code execution via unsafe deserialization of Xalan xsltc.trax.TemplatesImpl CVE-2021-39140 — xstream: Infinite loop DoS via unsafe deserialization of sun.reflect.annotation.AnnotationInvocationHandler CVE-2021-39141 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* CVE-2021-39144 — xstream: Arbitrary code execution via unsafe deserialization of sun.tracing.* CVE-2021-39145 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration CVE-2021-39146 — xstream: Arbitrary code execution via unsafe deserialization of javax.swing.UIDefaults$ProxyLazyValue CVE-2021-39147 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapSearchEnumeration CVE-2021-39148 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.toolkit.dir.ContextEnumerator CVE-2021-39149 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.corba.* CVE-2021-39150 — xstream: Server-side request forgery (SSRF) via unsafe deserialization of com.sun.xml.internal.ws.client.sei.* CVE-2021-39151 — xstream: Arbitrary code execution via unsafe deserialization of com.sun.jndi.ldap.LdapBindingEnumeration CVE-2021-39152 — xstream: Server-side request forgery (SSRF) via unsafe deserialization of jdk.nashorn.internal.runtime.Source$URLData CVE-2021-39153 — xstream: Arbitrary code execution via unsafe deserialization of Xalan xsltc.trax.TemplatesImpl CVE-2021-39154 — xstream: Arbitrary code execution via unsafe deserialization of javax.swing.UIDefaults$ProxyLazyValue
🎯 Affected products16
- Red Hat Enterprise Linux Client Optional (v. 7)
- Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- Red Hat Enterprise Linux Server Optional (v. 7)
- Red Hat Enterprise Linux Workstation Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
- xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7)
- xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7)
- xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7)
- xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2021:3956
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997763
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997765
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997769
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997772
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997775
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997777
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997779
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997781
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997784
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997786
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997791
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997793
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1997801
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3956.json