Known vulnerabilities in xstream (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:xstream_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 21
Public exploits: 6
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.5

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting xstream (Red Hat package) xstream (Red Hat package) is affected by 21 known vulnerabilities: 1 critical, 17 high, 3 medium Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73956 - Server-Side Request Forgery (SSRF)
CVE-2021-39152
CWE-918 High
Available
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73955 - Server-Side Request Forgery (SSRF)
CVE-2021-39150
CWE-918 High
Available
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73954 - Deserialization of Untrusted Data
CVE-2021-39151
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73953 - Deserialization of Untrusted Data
CVE-2021-39149
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73951 - Deserialization of Untrusted Data
CVE-2021-39148
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73950 - Deserialization of Untrusted Data
CVE-2021-39147
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73949 - Deserialization of Untrusted Data
CVE-2021-39146
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 11 more
#VU73948 - Deserialization of Untrusted Data
CVE-2021-39145
CWE-502 High
No
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 14 more
#VU73946 - Deserialization of Untrusted Data
CVE-2021-39141
CWE-502 High
Available
No
1.3.1-16.el7_9 22.03.2023 SB2021082322
SB2023032239
SB2023050815
and 14 more
#VU68720 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-39144
CWE-94 Critical
Available
Exploited
1.3.1-16.el7_9 25.10.2022 SB2021082322
SB2022102568
SB2023031801
and 17 more
#VU62511 - Improper input validation
CVE-2021-39140
CWE-20 Medium
No
No
1.3.1-16.el7_9 22.04.2022 SB2022042257
SB2023012518
SB2023032239
and 15 more
#VU60089 - Improper input validation
CVE-2021-39153
CWE-20 High
No
No
1.3.1-16.el7_9 27.01.2022 SB2022012755
SB2022042262
SB2023032239
and 13 more
#VU59813 - Improper input validation
CVE-2021-39139
CWE-20 High
No
No
1.3.1-16.el7_9 19.01.2022 SB2022011911
SB2022011912
SB2022012325
and 21 more
#VU59701 - Improper input validation
CVE-2021-39154
CWE-20 High
No
No
1.3.1-16.el7_9 18.01.2022 SB2022011835
SB2023032239
SB2023050815
and 12 more
#VU54675 - Deserialization of Untrusted Data
CVE-2021-29505
CWE-502 Medium
Available
No
1.3.1-14.el7_9 12.07.2021 SB2021071217
SB2021071218
SB2021071389
and 19 more
#VU52565 - Deserialization of Untrusted Data
CVE-2021-21350
CWE-502 High
No
No
1.3.1-13.el7_9 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52564 - Deserialization of Untrusted Data
CVE-2021-21347
CWE-502 High
No
No
1.3.1-13.el7_9 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52563 - Deserialization of Untrusted Data
CVE-2021-21346
CWE-502 High
No
No
1.3.1-13.el7_9 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 21 more
#VU52562 - Deserialization of Untrusted Data
CVE-2021-21345
CWE-502 High
No
No
1.3.1-13.el7_9 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 28 more
#VU52561 - Deserialization of Untrusted Data
CVE-2021-21344
CWE-502 High
No
No
1.3.1-13.el7_9 26.04.2021 SB2021042607
SB2021042608
SB2021043019
and 19 more


Showing elements 1 - 20 out of 21