RHSA-2020:4305: Moderate: java-11-openjdk security and bug fix update
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.Security Fix(es): OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781) OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782) OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) (CVE-2020-14792) OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797) OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803) OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779) OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Bug Fix(es): "java-11-openjdk-headless" scriptlet failed during RHEL7 > RHEL8 upgrade transaction (BZ#1871709) java-11-openjdk property java.vendor is "N/A" (BZ#1873390)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-debuginfo-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-debugsource-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-demo-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-devel-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-devel-debuginfo-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-headless-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-headless-debuginfo-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-javadoc-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-javadoc-zip-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-jmods-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-src-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-static-libs-11.0.9.11-0.el8_2 - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-debuginfo-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-debugsource-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-demo-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-devel-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-devel-debuginfo-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-headless-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-headless-debuginfo-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-javadoc-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-javadoc-zip-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-jmods-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-src-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
redhat/javato a version that resolves this vulnerability.Fixed in 11-openjdk-static-libs-11.0.9.11-0.el8_2.aa - Upgrade
Upgrade
java-11-openjdkto a version that resolves this vulnerability.Patch Moderate: java-11-openjdk security and bug fix update - Operational
Restart all running instances of OpenJDK Java for this update to take effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:4305?
The severity of RHSA-2020:4305 is classified as important.
How do I fix RHSA-2020:4305?
You can fix RHSA-2020:4305 by updating to the appropriate packages such as 11-openjdk-11.0.9.11-0.el8_2.
What vulnerabilities are addressed by RHSA-2020:4305?
RHSA-2020:4305 addresses vulnerabilities including CVE-2020-14781 related to unencrypted LDAP connections.
Which packages are affected by RHSA-2020:4305?
RHSA-2020:4305 affects several packages, including java-11-openjdk and its associated libraries.
Is user action required for RHSA-2020:4305?
Yes, user action is required to update the affected packages to mitigate the vulnerabilities.