RHSA-2023:1903HighCVSS 7.4

Red Hat Security Advisory: OpenJDK 8u372 Security Update for Portable Linux Builds

Published
April 25, 2023
Last Modified
September 7, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2023-21930 — OpenJDK: improper connection handling during TLS handshake (8294474) CVE-2023-21937 — OpenJDK: missing string checks for NULL characters (8296622) CVE-2023-21938 — OpenJDK: incorrect handling of NULL characters in ProcessBuilder (8295304) CVE-2023-21939 — OpenJDK: Swing HTML parsing issue (8296832) CVE-2023-21954 — OpenJDK: incorrect enqueue of references in garbage collector (8298191) CVE-2023-21967 — OpenJDK: certificate validation issue in TLS session negotiation (8298310) CVE-2023-21968 — OpenJDK: missing check for slash characters in URI-to-path conversion (8298667)

🎯 Affected products1

  • Red Hat Build of OpenJDK 8u362

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (10)