OpenJDK Vulnerability Advisory: 2020/01/14

The following vulnerabilities in OpenJDK source code were fixed in this release. The affected versions are 13.0.1, 11.0.5, 8u232, 7u241, and earlier. We recommend that you upgrade as soon as possible.

The current and previous advisories are available for reference.

Risk matrix

Affects ...
CVE ID Component CVSSv3
Vector
7 8 11 13
CVE-2020-2604 core-libs/
java.io:serialization
8.1
NHNNUHHH
CVE-2020-2601 security-libs/
java.security
6.8
NHNNCHNN
CVE-2020-2655 security-libs/
javax.net.ssl
4.8
NHNNULLN
CVE-2020-2593 core-libs/
java.net
4.8
NHNNULLN
CVE-2020-2654 security-libs/
java.security
3.7
NHNNUNNL
CVE-2020-2590 security-libs/
org.ietf.jgss
3.7
NHNNUNLN
CVE-2020-2659 core-libs/
java.nio
3.7
NHNNUNNL
CVE-2020-2583 client-libs/
java.beans
3.7
NHNNUNNL

Acknowledgements

We acknowledge the following parties for their reports and contributions: Paul Fiterau Brostean, Bengt Jonsson, Markus Loewe, Long Kuan, Robert Merget, Jonas Oezgan, Kostis Sagonas, Juraj Somorovsky, An Trinh, Bo Zhang, and Cheng Jing Wei.

We also thank the Leads of the JDK 7 Updates, JDK 8 Updates, and JDK 11 Updates Projects for providing the risk-matrix information for their releases.

How to report a vulnerability

Please see the reporting instructions for information about how to report a vulnerability.

Last update: 2020/01/14 17:10 UTC