#22347 closed enhancement (fixed)
jdk-21.0.9 (downgrade for security reasons)
| Reported by: | Douglas R. Reno | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version
At the moment due to the high severity security issues in JDK that are under active exploitation, it is a good idea to downgrade to 21.0.9. The reason why we aren't going to 25 yet is that there are several unfixed bugs that were not resolved in 25.0.1, which cause existing applications to no longer run and major problems with XML SAX support which cause programs such as fop, ant, maven, etc. to not build or run.
Downgrading to this LTS version is definitely the best approach for now. We can re-examine 25 when it's more stable, especially as it's the next LTS.
Vulnerabilities fixed in this release:
- CVE-2025-53066 - in the JAXP component. Actively exploited. Remotely exploitable without authentication or interaction, low attack complexity, and high confidentiality impact. With my Minecraft servers, this includes attackers trying to read /etc/passwd and other critical system information.
- CVE-2025-53057 - in the Security component. Remotely exploitable without user authentication or interaction, rated as Medium with high attack complexity.
- CVE-2025-61748 - in the Libraries component. Remotely exploitable without authentication, rated as Low with High attack complexity.
Change History (3)
comment:1 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 9 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Note:
See TracTickets
for help on using tickets.

Fixed at fcac90e8e4c73e9f2cd42ce512ae73c303396f5c
SA-12.4-067 issued