java-17-amazon-corretto

Direct Vulnerabilities

Known vulnerabilities in the java-17-amazon-corretto package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Certificate Validation

<1:17.0.20+8-1.amzn2023.1
  • H
Improper Certificate Validation

<1:17.0.20+8-1.amzn2023.1
  • H
Improper Verification of Cryptographic Signature

<1:17.0.20+8-1.amzn2023.1
  • H
NULL Pointer Dereference

<1:17.0.20+8-1.amzn2023.1
  • H
Out-of-bounds Write

<1:17.0.20+8-1.amzn2023.1
  • H
Inefficient Regular Expression Complexity

<1:17.0.20+8-1.amzn2023.1
  • H
Resource Exhaustion

<1:17.0.20+8-1.amzn2023.1
  • H
Resource Exhaustion

<1:17.0.20+8-1.amzn2023.1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.19+10-1.amzn2023.1
  • H
Cleartext Transmission of Sensitive Information

<1:17.0.19+10-1.amzn2023.1
  • H
Uncontrolled Recursion

<1:17.0.19+10-1.amzn2023.1
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:17.0.19+10-1.amzn2023.1
  • H
XML External Entity (XXE) Injection

<1:17.0.19+10-1.amzn2023.1
  • H
Out-of-bounds Read

<1:17.0.19+10-1.amzn2023.1
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:17.0.19+10-1.amzn2023.1
  • H
Improper Certificate Validation

<1:17.0.18+9-1.amzn2023.1
  • H
Improper Validation of Specified Type of Input

<1:17.0.18+9-1.amzn2023.1
  • H
CRLF Injection

<1:17.0.18+9-1.amzn2023.1
  • H
Key Exchange without Entity Authentication

<1:17.0.18+9-1.amzn2023.1
  • M
Inappropriate Encoding for Output Context

<1:17.0.17+10-1.amzn2023.1
  • M
CVE-2025-53066

<1:17.0.17+10-1.amzn2023.1
  • H
Information Exposure

<1:17.0.16+8-1.amzn2023.1
  • H
Missing Required Cryptographic Step

<1:17.0.16+8-1.amzn2023.1
  • H
Heap-based Buffer Overflow

<1:17.0.16+8-1.amzn2023.1
  • H
Heap-based Buffer Overflow

<1:17.0.16+8-1.amzn2023.1
  • H
Buffer Overflow

<1:17.0.15+6-1.amzn2023.1
  • H
Heap-based Buffer Overflow

<1:17.0.15+6-1.amzn2023.1
  • H
Information Exposure

<1:17.0.15+6-1.amzn2023.1
  • M
Signed to Unsigned Conversion Error

<1:17.0.14+7-1.amzn2023.1
  • M
Signed to Unsigned Conversion Error

<1:17.0.13+11-1.amzn2023.1
  • M
Uncontrolled Memory Allocation

<1:17.0.13+11-1.amzn2023.1
  • M
Integer Overflow or Wraparound

<1:17.0.13+11-1.amzn2023.1
  • M
Improper Handling of Length Parameter Inconsistency

<1:17.0.13+11-1.amzn2023.1
  • H
CVE-2024-21147

<1:17.0.12+7-1.amzn2023.1
  • H
CVE-2024-21140

<1:17.0.12+7-1.amzn2023.1
  • H
Out-of-bounds Write

<1:17.0.12+7-1.amzn2023.1
  • H
CVE-2024-21131

<1:17.0.12+7-1.amzn2023.1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.12+7-1.amzn2023.1
  • L
Integer Overflow or Wraparound

<1:17.0.11+9-1.amzn2023.1
  • L
Out-of-bounds Write

<1:17.0.11+9-1.amzn2023.1
  • L
Improper Output Neutralization for Logs

<1:17.0.11+9-1.amzn2023.1
  • L
Reliance on Reverse DNS Resolution for a Security-Critical Action

<1:17.0.11+9-1.amzn2023.1
  • H
CVE-2024-20925

<1:17.0.10+7-1.amzn2023.1
  • H
Covert Timing Channel

<1:17.0.10+7-1.amzn2023.1
  • H
Improper Input Validation

<1:17.0.10+7-1.amzn2023.1
  • H
CVE-2024-20923

<1:17.0.10+7-1.amzn2023.1
  • H
Information Exposure Through Log Files

<1:17.0.10+7-1.amzn2023.1
  • H
Improper Input Validation

<1:17.0.10+7-1.amzn2023.1
  • H
CVE-2024-20922

<1:17.0.10+7-1.amzn2023.1
  • H
Improper Input Validation

<1:17.0.10+7-1.amzn2023.1
  • H
Out-of-bounds Write

<1:17.0.10+7-1.amzn2023.1
  • M
Improper Certificate Validation

<1:17.0.9+8-1.amzn2023.1
  • M
Out-of-Bounds

<1:17.0.9+8-1.amzn2023.1
  • M
Allocation of Resources Without Limits or Throttling

<1:17.0.8+7-1.amzn2023.1
  • M
Directory Traversal

<1:17.0.8+7-1.amzn2023.1
  • M
Directory Traversal

<1:17.0.8+7-1.amzn2023.1
  • M
Out-of-bounds Read

<1:17.0.8+7-1.amzn2023.1
  • M
Out-of-bounds Read

<1:17.0.8+7-1.amzn2023.1
  • M
Small Space of Random Values

<1:17.0.8+7-1.amzn2023.1
  • M
CVE-2023-22043

<1:17.0.8+7-1.amzn2023.1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:17.0.8+7-1.amzn2023.1
  • H
Improperly Implemented Security Check for Standard

<1:17.0.7+7-1.amzn2023.1
  • H
Improper Input Validation

<1:17.0.7+7-1.amzn2023.1
  • H
Information Exposure

<1:17.0.7+7-1.amzn2023.1
  • H
Improper Input Validation

<1:17.0.7+7-1.amzn2023.1
  • H
Improper Neutralization of Null Byte or NUL Character

<1:17.0.7+7-1.amzn2023.1
  • H
Improper Neutralization of Null Byte or NUL Character

<1:17.0.7+7-1.amzn2023.1
  • H
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1:17.0.7+7-1.amzn2023.1