﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
16822	Update to OpenJDK-18.0.2 to fix CVE-2022-34169, CVE-2022-21541, and CVE-2022-21540	Douglas R. Reno	Douglas R. Reno	"There is a new security vulnerability in OpenJDK that allows for corruption of Java class files and for arbitrary code execution. It occurs in the Apache Xalan Java XSLT Library which is bundled directly into the OpenJDK interpreter.

No future releases of Xalan are expected, but the OpenJDK folks do have it patched upstream:

[https://github.com/openjdk/jdk/commit/41ef2b249073450172e11163a4d05762364b1297]

The problem is an integer truncation issue that occurs when processing malicious XSLT stylesheets.

Looking over at [https://openjdk.org/groups/vulnerability/advisories/2022-07-19], it looks like this and two other security vulnerabilities have been addressed. This vulnerability has been rated at 7.5, while CVE-2022-21541 has been rated 5.9 and CVE-2022-21540 has been rated 5.3.

[https://jdk.java.net/18/] shows that 18.0.2 has been released"	enhancement	closed	high	11.2	BOOK	git	medium	fixed		
