First published: Sun Apr 12 2020(Updated: )
A flaw was found in the Security component of OpenJDK. It was discovered that the unmarshalKeyInfo() method of the DOMKeyInfoFactory class and the unmarshalXMLSignature() method of the DOMXMLSignatureFactory class could raise exceptions not declared as thrown by these methods when reading key info or XML signature data from XML input.
Affected Software | Affected Version | How to fix |
---|---|---|
OpenJDK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1823224 is considered to be moderate.
To fix REDHAT-BUG-1823224, update your OpenJDK to the latest version provided by the vendor.
All supported versions of OpenJDK that utilize the vulnerable methods are affected by REDHAT-BUG-1823224.
The flaw in REDHAT-BUG-1823224 allows exceptions to be raised by certain methods that are not declared as throwable.
Currently, the recommended action for REDHAT-BUG-1823224 is to apply the provided updates rather than using a workaround.