﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
18192	jdk-20.0.1	Douglas R. Reno	Douglas R. Reno	"New major version

This seems to be a rather significant security update that'll probably go pretty high on my priority list for this week since Pierre is out of town:

""This Critical Patch Update contains 8 new security patches, plus additional third party patches noted below, for Oracle Java SE.  7 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a network without requiring user credentials.""

(In our case, all of these require no authentication)

The table shows that we are vulnerable to:

CVE-2023-21930 - High severity in the TLS component. Attack complexity is high, but it does allow for unauthorized creation, modification, or deletion of data.

CVE-2023-21967 - Medium severity in the HTTPS component. Denial of service with high attack complexity.

CVE-2023-21939 - Medium severity in the Swing component. **Attack Complexity is trivial and allows for unauthorized creation, modification, or deletion of data.**

CVE-2023-21938 - Low severity in multiple libraries. High attack complexity, but allows for unauthorized creation, modification, or deletion of data.

CVE-2023-21968 - Low severity in multiple libraries. High attack complexity, but allows for unauthorized creation, modification, or deletion of data.

CVE-2023-21937 - Low severity in the networking component. High attack complexity, but allows for unauthorized creation, modification, or deletion of data."	enhancement	closed	high	12.0	BOOK	git	medium	fixed		
