QID 378794

QID 378794: Red Hat OpenJDK 8u382 Windows Builds release and Security Update (RHSA-2023:4212)

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049).

OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045).
Affected Versions:
Red Hat build of OpenJDK 8 (8u372) and later Versions and Prior to OpenJDK 8 (8u382)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data .

  • CVSS V3 rated as Medium - 3.7 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    For more information regarding the update RHSA-2023:4212
    Vendor References

    CVEs related to QID 378794

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2023:4212 URL Logo access.redhat.com/errata/RHSA-2023:4212