﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22347	jdk-21.0.9 (downgrade for security reasons)	Douglas R. Reno	Douglas R. Reno	"New point version

At the moment due to the high severity security issues in JDK that are under active exploitation, it is a good idea to downgrade to 21.0.9. The reason why we aren't going to 25 yet is that there are several unfixed bugs that were not resolved in 25.0.1, which cause existing applications to no longer run and major problems with XML SAX support which cause programs such as fop, ant, maven, etc. to not build or run.

Downgrading to this LTS version is definitely the best approach for now. We can re-examine 25 when it's more stable, especially as it's the next LTS.

Vulnerabilities fixed in this release:

- CVE-2025-53066 - in the JAXP component. Actively exploited. Remotely exploitable without authentication or interaction, low attack complexity, and high confidentiality impact. With my Minecraft servers, this includes attackers trying to read /etc/passwd and other critical system information.

- CVE-2025-53057 - in the Security component. Remotely exploitable without user authentication or interaction, rated as Medium with high attack complexity.

- CVE-2025-61748 - in the Libraries component. Remotely exploitable without authentication, rated as Low with High attack complexity."	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
