First published: Wed Feb 05 2025(Updated: )
It was discovered that the Hotspot component of OpenJDK 23 did not properly handle API access under certain circumstances. An unauthenticated attacker could possibly use this issue to access unauthorized resources and expose sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/openjdk-23-jdk | <23.0.2+7-1ubuntu1~24.10 | 23.0.2+7-1ubuntu1~24.10 |
Xfce Application Finder | =24.10 | |
All of | ||
ubuntu/openjdk-23-jdk-headless | <23.0.2+7-1ubuntu1~24.10 | 23.0.2+7-1ubuntu1~24.10 |
Xfce Application Finder | =24.10 | |
All of | ||
ubuntu/openjdk-23-jre | <23.0.2+7-1ubuntu1~24.10 | 23.0.2+7-1ubuntu1~24.10 |
Xfce Application Finder | =24.10 | |
All of | ||
ubuntu/openjdk-23-jre-headless | <23.0.2+7-1ubuntu1~24.10 | 23.0.2+7-1ubuntu1~24.10 |
Xfce Application Finder | =24.10 | |
All of | ||
ubuntu/openjdk-23-jre-zero | <23.0.2+7-1ubuntu1~24.10 | 23.0.2+7-1ubuntu1~24.10 |
Xfce Application Finder | =24.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7255-1 is significant, as it allows unauthenticated attackers to access unauthorized resources.
To fix USN-7255-1, update to the version 23.0.2+7-1ubuntu1~24.10 of the affected OpenJDK packages.
USN-7255-1 affects the OpenJDK 23 Hotspot component, specifically various OpenJDK packages available on Ubuntu 24.10.
Users of OpenJDK 23 on Ubuntu 24.10 are vulnerable to the issues outlined in USN-7255-1.
USN-7255-1 pertains to an attack that could allow access to unauthorized resources and exposure of sensitive information.