RHSA-2021:2780: Important: OpenJDK 11.0.12 Security Update for Portable Linux Builds
The OpenJDK 11 packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.This release of the Red Hat build of OpenJDK 11 (11.0.12) for portable Linux serves as a replacement for the Red Hat build of OpenJDK 11 (11.0.11) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.Security Fix(es): OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2021:2780?
The severity of RHSA-2021:2780 is classified as important.
How do I fix RHSA-2021:2780?
To fix RHSA-2021:2780, update to the latest version of OpenJDK 11 as recommended in the advisory.
What vulnerabilities does RHSA-2021:2780 address?
RHSA-2021:2780 addresses multiple security vulnerabilities in OpenJDK 11 that could potentially lead to security breaches.
Is my system affected by RHSA-2021:2780?
Your system may be affected by RHSA-2021:2780 if you are running an outdated version of OpenJDK 11 prior to 11.0.12.
What impact does RHSA-2021:2780 have on applications?
RHSA-2021:2780 can impact applications that rely on the OpenJDK 11 runtime if the vulnerabilities are exploited.