CVE-2023-21835
A flaw was discovered in the DTLS in JSSE component of OpenJDK, allowing malicious clients to make a DTLS server consume excessive resources by repeatedly transmitting a series of handshake initiation requests. The malicious client could also use this flaw to send pre-generated messages with a spoofed source, causing the server to send replies to a victim machine, thus potentially flooding it.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-21835?
CVE-2023-21835 is a vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE, specifically in the JSSE component.
What is the severity of CVE-2023-21835?
CVE-2023-21835 has a severity value of 5.3, which is classified as medium severity.
Which versions of Oracle Java SE and Oracle GraalVM Enterprise Edition are affected by CVE-2023-21835?
The affected versions are Oracle Java SE 11.0.17, 17.0.5, 19.0.1, Oracle GraalVM Enterprise Edition 20.3.8, 21.3.4, and 22.3.0.
How do I fix CVE-2023-21835?
To fix CVE-2023-21835, you should update to the following versions: Oracle Java SE 11.0.18, 17.0.6, 19.0.3, Oracle GraalVM Enterprise Edition 21.3.5, 22.3.1.
Where can I find more information about CVE-2023-21835?
You can find more information about CVE-2023-21835 in the following references: [Reference 1](https://github.com/openjdk/jdk17u/commit/04f32aacb592cd8f9c963278f01310a138a940ff), [Reference 2](https://github.com/openjdk/jdk11u/commit/57f29406b9d729a69410113518094f641c5799ea), [Reference 3](https://access.redhat.com/errata/RHSA-2023:0202).