REDHAT-BUG-2075849: Medium severity OpenJDK JNDI component (java.net.URI / com.sun.jndi.toolkit.url.URI parsing) vulnerability
Inconsistencies were found in the way the java.net.URI and com.sun.jndi.toolkit.url.URI classes in the JNDI component of OpenJDK parsed URI strings. These inconsistencies could be used to make a Java application accept invalid or malformed URI strings.
Parsing of URL strings in built-in JNDI providers were made more strict as part of the fix. For more information, see the following release notes for Oracle JDK 7u341, 8u331, 11.0.15, 17.0.3, 18.0.1:
https://www.oracle.com/java/technologies/javase/7-support-relnotes.html#JDK-8278972 https://www.oracle.com/java/technologies/javase/8u331-relnotes.html#JDK-8278972 https://www.oracle.com/java/technologies/javase/11-0-15-relnotes.html#JDK-8278972 https://www.oracle.com/java/technologies/javase/17-0-3-relnotes.html#JDK-8278972 https://www.oracle.com/java/technologies/javase/18-0-1-relnotes.html#JDK-8278972
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7u341 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8u331 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.0.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2075849?
The severity of REDHAT-BUG-2075849 is classified as critical due to the potential for malicious exploitation.
How do I fix REDHAT-BUG-2075849?
To fix REDHAT-BUG-2075849, update your OpenJDK or Oracle JDK to the latest patched version.
What applications are affected by REDHAT-BUG-2075849?
REDHAT-BUG-2075849 affects applications using the java.net.URI and com.sun.jndi.toolkit.url.URI classes in the JNDI component.
What type of vulnerabilities does REDHAT-BUG-2075849 involve?
REDHAT-BUG-2075849 involves URI parsing inconsistencies that can lead to the acceptance of malformed URI strings.
Can REDHAT-BUG-2075849 lead to security breaches?
Yes, REDHAT-BUG-2075849 can lead to security breaches if a Java application accepts and processes malformed URIs.