REDHAT-BUG-1471738: High severity openjdk 8 vulnerability
It was discovered that the LDAPCertStore class in the Security component of OpenJDK followed LDAP referrals to arbitrary URLs. A specially-crafted LDAP referral URL could cause LDAPCertStore to communicate with non-LDAP servers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1471738?
The severity of REDHAT-BUG-1471738 is classified as critical due to the potential for unauthorized communication with non-LDAP servers.
How do I fix REDHAT-BUG-1471738?
To fix REDHAT-BUG-1471738, update your Oracle OpenJDK to the latest version provided by your vendor that addresses the vulnerability.
What versions of OpenJDK are affected by REDHAT-BUG-1471738?
The affected versions of OpenJDK include Oracle OpenJDK 17 and potentially other unpatched versions.
What are the potential risks associated with REDHAT-BUG-1471738?
The potential risks associated with REDHAT-BUG-1471738 include exposure to data leaks and communication with malicious non-LDAP services.
Is there a workaround for REDHAT-BUG-1471738?
Currently, there are no documented workarounds for REDHAT-BUG-1471738, so applying the appropriate patches is the recommended course of action.