QID 378130

Date Published: 2023-04-04

QID 378130: Red Hat OpenJDK 8u302 Windows Builds release and Security Update (RHSA-2021:2777)

P>The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341).

OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369)

OpenJDK: Incorrect comparison during range check elimination (Hotspot,8264066) (CVE-2021-2388)
Affected Versions:
Red Hat build of OpenJDK 8 (1.8.0.292) and later Versions and Prior to OpenJDK 8 (1.8.0.302)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    For more information regarding the update RHSA-2021:2777
    Vendor References

    CVEs related to QID 378130

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2021:2777 URL Logo access.redhat.com/errata/RHSA-2021:2777