java-21-amazon-corretto vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the java-21-amazon-corretto package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Signed to Unsigned Conversion Error

<1:21.0.6+7-1.amzn2023.1
  • M
Integer Overflow or Wraparound

<1:21.0.5+11-1.amzn2023.1
  • M
Uncontrolled Memory Allocation

<1:21.0.5+11-1.amzn2023.1
  • M
Improper Handling of Length Parameter Inconsistency

<1:21.0.5+11-1.amzn2023.1
  • M
Signed to Unsigned Conversion Error

<1:21.0.5+11-1.amzn2023.1
  • H
Out-of-bounds Read

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21131

<1:21.0.4+7-1.amzn2023.1
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21147

<1:21.0.4+7-1.amzn2023.1
  • H
CVE-2024-21140

<1:21.0.4+7-1.amzn2023.1
  • L
Improper Output Neutralization for Logs

<1:21.0.3+9-1.amzn2023.1
  • L
Out-of-bounds Write

<1:21.0.3+9-1.amzn2023.1
  • L
Reliance on Reverse DNS Resolution for a Security-Critical Action

<1:21.0.3+9-1.amzn2023.1
  • L
Integer Overflow or Wraparound

<1:21.0.3+9-1.amzn2023.1
  • H
Covert Timing Channel

<1:21.0.2+13-1.amzn2023.1
  • H
Improper Input Validation

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20922

<1:21.0.2+13-1.amzn2023.1
  • H
Improper Input Validation

<1:21.0.2+13-1.amzn2023.1
  • H
Information Exposure Through Log Files

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20923

<1:21.0.2+13-1.amzn2023.1
  • H
Integer Overflow or Wraparound

<1:21.0.2+13-1.amzn2023.1
  • H
CVE-2024-20925

<1:21.0.2+13-1.amzn2023.1
  • M
Out-of-Bounds

<1:21.0.1+12-1.amzn2023.1
  • M
Improper Certificate Validation

<1:21.0.1+12-1.amzn2023.1