The host is missing a critical security update according to Adobe advisory, APSB21-53. The update is required to fix multiple vulnerabilities. The flaws are present in the application, which fails to handle unspecified vectors. Successful exploitation could allow attackers to execute arbitrary code.
The host is installed with Adobe Bridge 11.0.2 and earlier and is prone to an improper input validation vulnerability. A flaw is present in the application, which fails to handle unspecified vectors. Successful exploitation could allow attackers to execute arbitrary code.
The host is installed with Jenkins LTS through 2.319.2 or Jenkins rolling through 2.333 and is prone to a denial of service vulnerability. A flaw is present in the application, which fails to handle XStream that is used by Jenkins to serialize and deseralize various XML files. Successful exploitation could allow attackers to cause denial of service.
The host is installed with Jenkins LTS before 2.319.3 or Jenkins rolling release before 2.255.334 and is prone to a denial of service vulnerability. A flaw is present in the application, which fails to handle XStream library. Successful exploitation could allow attakers to use unconstrained resource.
openjdk-17: Open Source Java implementation - openjdk-20: Open Source Java implementation - openjdk-8: Open Source Java implementation - openjdk-lts: Open Source Java implementation Several security issues were fixed in OpenJDK.
This update for java-11-openjdk fixes the following issues: Upgrade to upsteam tag jdk-11.0.19+7 : * CVE-2023-21930: Fixed AES support . * CVE-2023-21937: Fixed String platform support . * CVE-2023-21938: Fixed runtime support . * CVE-2023-21939: Fixed Swing platform support . * CVE-2023-21954: Fixed object reclamation process . * CVE-2023-21967: Fixed TLS session negotiation . * CVE-2023-21968: F ...
This update for java-11-openjdk fixes the following issues: Upgrade to upsteam tag jdk-11.0.19+7 : * CVE-2023-21930: Fixed AES support . * CVE-2023-21937: Fixed String platform support . * CVE-2023-21938: Fixed runtime support . * CVE-2023-21939: Fixed Swing platform support . * CVE-2023-21954: Fixed object reclamation process . * CVE-2023-21967: Fixed TLS session negotiation . * CVE-2023-21968: F ...
This update for java-1_8_0-openjdk fixes the following issues: * Updated to version jdk8u372 : * CVE-2023-21930: Fixed an issue in the JSSE component that could allow an attacker to access critical data without authorization . * CVE-2023-21937: Fixed an issue in the Networking component that could allow an attacker to update, insert or delete some data without authorization . * CVE-2023-21938: Fix ...