CVE-2020-2767: Medium severity Oracle JDK vulnerability
A flaw was found in the way the TLS implementation in the JSSE component of OpenJDK handled unexpected Certificate messages during the TLS handshake. This could possibly allow an attacker to tamper with certificate verification performed during the handshake.
Other sources
Vulnerability in the Java SE product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 11.0.6 and 14. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE accessible data as well as unauthorized read access to a subset of Java SE accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2767?
CVE-2020-2767 has a CVSS score of 7.5, indicating it is of high severity.
How do I fix CVE-2020-2767?
To fix CVE-2020-2767, upgrade to a patched version of OpenJDK or Oracle JDK as specified in the vulnerability advisory.
Is CVE-2020-2767 exploitable remotely?
Yes, CVE-2020-2767 can be exploited remotely in scenarios where an attacker can intercept and manipulate TLS handshake messages.
What versions of OpenJDK are affected by CVE-2020-2767?
CVE-2020-2767 affects OpenJDK versions 11.0.6 and earlier; specific versions include 11-openjdk-1:11.0.7.10-4.el7_8 and 11-openjdk-1:11.0.7.10-1.el8_1.
Are there any specific platforms vulnerable to CVE-2020-2767?
Yes, CVE-2020-2767 affects multiple platforms including Red Hat and Debian distributions, particularly with the specified vulnerable OpenJDK packages.