CVE-2023-21967: Medium severity Oracle GraalVM vulnerability
It was discovered that the TLS implementation in the JSSE component of OpenJDK failed to properly handle certificate chains during TLS session negotiation. A remote attacker attacker could use this flaw to affect the availability of a TLS connection (denial-of-service condition).
Other sources
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; Oracle GraalVM Enterprise Edition: 20.3.9, 21.3.5 and 22.3.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Oracle Java SE vulnerability?
The vulnerability ID is CVE-2023-21967.
What is the affected software?
The affected software includes Oracle Java SE versions 8u361, 8u361-perf, 11.0.18, 17.0.6, 20; and Oracle GraalVM Enterprise Edition versions 20.3.9, 21.3.5, and 22.3.1.
How severe is this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.9.
Is it difficult to exploit this vulnerability?
It is difficult to exploit this vulnerability.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [GitHub Commit 1](https://github.com/openjdk/jdk8u/commit/71bb00a5d86affa8c2c8934ab892fe6c5191abdc), [GitHub Commit 2](https://github.com/openjdk/jdk11u/commit/4a4f5c528c8b59669e5cc1df1b0e1ad9eb44497b), [GitHub Commit 3](https://github.com/openjdk/jdk17u/commit/0e679760884bb7315c38db37dddf4dfc90f4e1de).