CyberzSOC

Applicability
← Back to CVE-2021-39144

CVE-2021-39144

In CISA KEV XStream

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

Red Hat CSAF/VEX
precedence 100 · revised 2026-08-08
9 affected 19 fixed 19 not affected
OSV.dev (incl. GHSA)
precedence 80 · revised 2026-07-08
2 affected 2 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-10-21
1 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (52)

Product Status Versions Remediation Source
red_hat_bpm_suite_6:xstream xstream as a component of Red Hat BPM Suite 6 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
red_hat_integration_camel_quarkus_1:xstream xstream as a component of Red Hat Integration Camel Quarkus 1 affected no version stated vendor label: xstream none available fix in another branch csaf_redhat
red_hat_jboss_a-mq_6:xstream xstream as a component of Red Hat JBoss A-MQ 6 affected no version stated vendor label: xstream none available fix in another branch csaf_redhat
red_hat_jboss_brms_5:xstream xstream as a component of Red Hat JBoss BRMS 5 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
red_hat_jboss_brms_6:xstream xstream as a component of Red Hat JBoss BRMS 6 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
red_hat_jboss_data_virtualization_6:xstream xstream as a component of Red Hat JBoss Data Virtualization 6 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
red_hat_jboss_fuse_6:xstream xstream as a component of Red Hat JBoss Fuse 6 affected no version stated vendor label: xstream none available fix in another branch csaf_redhat
red_hat_jboss_fuse_service_works_6:xstream xstream as a component of Red Hat JBoss Fuse Service Works 6 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
red_hat_jboss_soa_platform_5:xstream xstream as a component of Red Hat JBoss SOA Platform 5 affected no version stated vendor label: xstream out of support fix in another branch csaf_redhat
Red Hat Data Grid 7.3.10 fixed no version stated vendor fix csaf_redhat
Red Hat Data Grid 8.3.0 fixed no version stated vendor fix csaf_redhat
Red Hat Integration fixed no version stated vendor fix csaf_redhat
Red Hat Integration Camel Quarkus 2 fixed no version stated vendor fix csaf_redhat
Red Hat Single Sign-On 7 fixed no version stated vendor fix csaf_redhat
RHDM 7.12.0 fixed no version stated vendor fix csaf_redhat
RHPAM 7.12.0 fixed no version stated vendor fix csaf_redhat
7Client-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.noarch xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.noarch vendor fix → xstream-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7ComputeNode-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.noarch xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.noarch vendor fix → xstream-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7Server-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.noarch xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.noarch vendor fix → xstream-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7Workstation-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.noarch xstream-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.noarch vendor fix → xstream-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7Client-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.src xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Client Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.src vendor fix → xstream-0:1.3.1-16.el7_9.src (RHSA-2021:3956) csaf_redhat
7ComputeNode-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.src xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.src vendor fix → xstream-0:1.3.1-16.el7_9.src (RHSA-2021:3956) csaf_redhat
7Server-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.src xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Server Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.src vendor fix → xstream-0:1.3.1-16.el7_9.src (RHSA-2021:3956) csaf_redhat
7Workstation-optional-7.9.Z:xstream-0:1.3.1-16.el7_9.src xstream-0:1.3.1-16.el7_9.src as a component of Red Hat Enterprise Linux Workstation Optional (v. 7) fixed xstream-0:1.3.1-16.el7_9.src vendor fix → xstream-0:1.3.1-16.el7_9.src (RHSA-2021:3956) csaf_redhat
7Client-optional-7.9.Z:xstream-javadoc-0:1.3.1-16.el7_9.noarch xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Client Optional (v. 7) fixed xstream-javadoc-0:1.3.1-16.el7_9.noarch vendor fix → xstream-javadoc-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7ComputeNode-optional-7.9.Z:xstream-javadoc-0:1.3.1-16.el7_9.noarch xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux ComputeNode Optional (v. 7) fixed xstream-javadoc-0:1.3.1-16.el7_9.noarch vendor fix → xstream-javadoc-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7Server-optional-7.9.Z:xstream-javadoc-0:1.3.1-16.el7_9.noarch xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Server Optional (v. 7) fixed xstream-javadoc-0:1.3.1-16.el7_9.noarch vendor fix → xstream-javadoc-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
7Workstation-optional-7.9.Z:xstream-javadoc-0:1.3.1-16.el7_9.noarch xstream-javadoc-0:1.3.1-16.el7_9.noarch as a component of Red Hat Enterprise Linux Workstation Optional (v. 7) fixed xstream-javadoc-0:1.3.1-16.el7_9.noarch vendor fix → xstream-javadoc-0:1.3.1-16.el7_9.noarch (RHSA-2021:3956) csaf_redhat
red_hat_openshift_container_platform_3.11:jenkins jenkins as a component of Red Hat OpenShift Container Platform 3.11 not affected vulnerable code not present no version stated vendor label: jenkins not applicable csaf_redhat
red_hat_openshift_container_platform_4:jenkins jenkins as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present no version stated vendor label: jenkins not applicable csaf_redhat
openshift_developer_tools_and_services:jenkins.src jenkins.src as a component of OpenShift Developer Tools and Services not affected vulnerable code not present no version stated vendor label: jenkins.src not applicable csaf_redhat
red_hat_openshift_container_platform_3.11:jenkins.src jenkins.src as a component of Red Hat OpenShift Container Platform 3.11 not affected vulnerable code not present no version stated vendor label: jenkins.src not applicable csaf_redhat
red_hat_openshift_container_platform_4:jenkins.src jenkins.src as a component of Red Hat OpenShift Container Platform 4 not affected vulnerable code not present no version stated vendor label: jenkins.src not applicable csaf_redhat
logging_subsystem_for_red_hat_openshift:openshift-logging/elasticsearch6-rhel8 openshift-logging/elasticsearch6-rhel8 as a component of Logging Subsystem for Red Hat OpenShift not affected vulnerable code not present openshift-logging/elasticsearch6-rhel8 not applicable csaf_redhat
migration_toolkit_for_applications_6:org.keycloak-keycloak-parent.src org.keycloak-keycloak-parent.src as a component of Migration Toolkit for Applications 6 not affected vulnerable code not present no version stated vendor label: org.keycloak-keycloak-parent.src not applicable csaf_redhat
migration_toolkit_for_runtimes:org.keycloak-keycloak-parent.src org.keycloak-keycloak-parent.src as a component of Migration Toolkit for Runtimes not affected vulnerable code not present no version stated vendor label: org.keycloak-keycloak-parent.src not applicable csaf_redhat
a-mq_clients_2:xstream xstream as a component of A-MQ Clients 2 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_amq_broker_7:xstream xstream as a component of Red Hat AMQ Broker 7 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_build_of_apache_camel_for_spring_boot_3:xstream xstream as a component of Red Hat build of Apache Camel for Spring Boot 3 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_build_of_apicurio_registry_2:xstream xstream as a component of Red Hat build of Apicurio Registry 2 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_build_of_debezium_1:xstream xstream as a component of Red Hat build of Debezium 1 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_build_of_quarkus:xstream xstream as a component of Red Hat build of Quarkus not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_fuse_7:xstream xstream as a component of Red Hat Fuse 7 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_6:xstream xstream as a component of Red Hat JBoss Enterprise Application Platform 6 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_7:xstream xstream as a component of Red Hat JBoss Enterprise Application Platform 7 not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_jboss_enterprise_application_platform_expansion_pack:xstream xstream as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
red_hat_openshift_application_runtimes:xstream xstream as a component of Red Hat OpenShift Application Runtimes not affected vulnerable code not present no version stated vendor label: xstream not applicable csaf_redhat
com.thoughtworks.xstream:xstream affected < 1.4.18 vendor fix → 1.4.18 osv GHSA-j9h8-phrw-h4fh
https://github.com/x-stream/xstream affected < b9ad1c02724c2b1636a8794c8e1bcd630f46c0b3 vendor fix → b9ad1c02724c2b1636a8794c8e1bcd630f46c0b3 osv
com.thoughtworks.xstream:xstream fixed 1.4.18 vendor fix → 1.4.18 osv GHSA-j9h8-phrw-h4fh
https://github.com/x-stream/xstream fixed b9ad1c02724c2b1636a8794c8e1bcd630f46c0b3 vendor fix → b9ad1c02724c2b1636a8794c8e1bcd630f46c0b3 osv
x-stream/xstream x-stream · xstream affected < 1.4.18 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.