RHSA-2023:1903HighCVSS 7.4
Red Hat Security Advisory: OpenJDK 8u372 Security Update for Portable Linux Builds
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-21930 — OpenJDK: improper connection handling during TLS handshake (8294474) CVE-2023-21937 — OpenJDK: missing string checks for NULL characters (8296622) CVE-2023-21938 — OpenJDK: incorrect handling of NULL characters in ProcessBuilder (8295304) CVE-2023-21939 — OpenJDK: Swing HTML parsing issue (8296832) CVE-2023-21954 — OpenJDK: incorrect enqueue of references in garbage collector (8298191) CVE-2023-21967 — OpenJDK: certificate validation issue in TLS session negotiation (8298310) CVE-2023-21968 — OpenJDK: missing check for slash characters in URI-to-path conversion (8298667)
🎯 Affected products1
- Red Hat Build of OpenJDK 8u362
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2023:1903
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187435
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187441
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187704
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187724
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187758
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187790
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2187802
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_1903.json