OpenJDK Vulnerability Advisory: 2023/10/17
The following vulnerabilities in OpenJDK source code were fixed in this release. The affected versions are 21, 17.0.8, 11.0.20, 8u382, and earlier. Please note that defense-in-depth issues are not assigned CVEs. We recommend that you upgrade as soon as possible.
The current and previous advisories are available for reference.
OpenJDK Risk matrix
| Affects ... | ||||||
|---|---|---|---|---|---|---|
| CVE ID | Component | CVSSv3.1 Vector  | 
8 | 11 | 17 | 21 | 
| CVE-2023-22067 | other-libs/ corba  | 
5.3 NLNNUNLN  | 
• | |||
| CVE-2023-22081 | security-libs/ javax.net.ssl  | 
5.3 NLNNUNNL  | 
• | • | • | • | 
| CVE-2023-22025 | hotspot/ compiler  | 
3.7 NHNNUNLN  | 
• | • | ||
OpenJFX Risk matrix
| Affects ... | |||||
|---|---|---|---|---|---|
| CVE ID | Component | CVSSv3.1 Vector  | 
11 | 17 | 21 | 
| None | |||||
Acknowledgements
We acknowledge the following parties for their reports and contributions: Carter Kozak, and Dinglijie.
We also thank the Leads of the JDK 8 Updates, JDK 11 Updates, JDK 17 Updates, and OpenJFX Projects for providing the risk-matrix information for their releases.
How to report a vulnerability
Please see the reporting instructions for information about how to report a vulnerability.
Last update: 2023/10/17 17:44 UTC