OpenJDK Vulnerability Advisory: 2020/10/20

The following vulnerabilities in OpenJDK source code were fixed in this release. The affected versions are 15, 13.0.4, 11.0.8, 8u262, 7u271, and earlier. We recommend that you upgrade as soon as possible.

The current and previous advisories are available for reference.

OpenJDK Risk matrix

Affects ...
CVE ID Component CVSSv3.1
Vector
7 8 11 13 15
CVE-2020-14803 core-libs/
java.io
5.3
NLNNULNN
CVE-2020-14792 hotspot/
compiler
4.2
NHNRULLN
CVE-2020-14782 security-libs/
java.security
3.7
NHNNUNLN
CVE-2020-14797 core-libs/
java.nio
3.7
NHNNUNLN
CVE-2020-14781 core-libs/
javax.naming
3.7
NHNNULNN
CVE-2020-14779 core-libs/
java.io:serialization
3.7
NHNNUNNL
CVE-2020-14796 core-libs/
java.io
3.1
NHNRULNN
CVE-2020-14798 core-libs/
java.io
3.1
NHNRUNLN

OpenJFX Risk matrix

Affects ...
CVE ID Component CVSSv3.1
Vector
7 8 11 13 15
None

Acknowledgements

We acknowledge the following parties for their reports and contributions: Andreas Brehmer, Hedongbo, Markus Loewe, Sergey, Tony Homer, and Zhiqiang Zang.

We also thank the Leads of the JDK 7 Updates, JDK 8 Updates, JDK 11 Updates, JDK 13 Updates, and OpenJFX Projects for providing the risk-matrix information for their releases.

How to report a vulnerability

Please see the reporting instructions for information about how to report a vulnerability.

Last update: 2020/10/20 17:14 UTC