﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
16453	jdk-18.0.1	Douglas R. Reno	pierre	"New point version

Found at [https://github.com/openjdk/jdk17u/archive/refs/tags/jdk-17.0.3-ga.tar.gz]

Unfortunately, due to the severity of the vulnerabilities fixed in this release, and the publicly-available nature of them, it really needs to be ""High"" instead of elevated.

Here's some information on the major cryptography vulnerability: [https://nakedsecurity.sophos.com/2022/04/20/critical-cryptographic-java-security-blunder-patched-update-now/]

Oracle's Critical Product Update (note that it also has 37 CVEs for MySQL, so we might get hit by those in MariaDB) contains the following fixes for Java (see [https://www.oracle.com/security-alerts/cpuapr2022verbose.html#JAVA]):

CVE-2022-21426 - remote unauthenticated denial of service

CVE-2022-21434 - remote unauthenticated update/insert/delete access to data stored in Java, or that the Java process has access to

CVE-2022-21443 - remote unauthenticated denial of service

CVE-2022-21449 - remote unautenticated creation, deletion, or modification of files/data

CVE-2022-21476 - remote unauthenticated access to data (information disclosure)

CVE-2022-21496 - remote unauthenticated modification of data

As the notes say: ""All of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials."""	enhancement	closed	high	11.2	BOOK	git	medium	fixed		
