QID 378563

Date Published: 2023-06-19

QID 378563: Red Hat OpenJDK 8u372 Windows Builds release and Security Update (RHSA-2023:1912)

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

OpenJDK: improper connection handling during TLS handshake (8294474) (CVE-2023-21930).

OpenJDK: Swing HTML parsing issue (8296832) (CVE-2023-21939).

OpenJDK: incorrect enqueue of references in garbage collector (8298191) (CVE-2023-21954).

OpenJDK: certificate validation issue in TLS session negotiation (8298310) (CVE-2023-21967).

OpenJDK: missing string checks for NULL characters (8296622) (CVE-2023-21937).

OpenJDK: incorrect handling of NULL characters in ProcessBuilder (8295304) (CVE-2023-21938).

OpenJDK: missing check for slash characters in URI-to-path conversion (8298667) (CVE-2023-21968).
Affected Versions:
Red Hat build of OpenJDK 8 (8u362) and later Versions and Prior to OpenJDK 8 (8u372)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data .

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    For more information regarding the update RHSA-2023:1912
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2023:1912 URL Logo access.redhat.com/errata/RHSA-2023:1912