Information Disclosure Affecting openjdk-jre package, versions [1.7.0,1.7.0_281) [1.8.0,1.8.0_271) [11.0.0,11.0.9) [15.0.0,15.0.1)
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UPSTREAM-OPENJDKJRE-1020125
- published 21 Oct 2020
- disclosed 20 Oct 2020
- credit Sergey Ostanin
Introduced: 20 Oct 2020
CVE-2020-14781 Open this link in a new tabHow to fix?
Upgrade openjdk-jre
to version 7.0.281, 8.0.271, 11.0.9, 15.0.1 or higher.
Overview
openjdk-jre is a free and open-source implementation of the Java Platform, Standard Edition (Java SE).
Affected versions of this package are vulnerable to Information Disclosure. It was discovered that the LDAP client implementation in the JNDI component of OpenJDK did not properly track whether a connection to a server uses TLS encryption, and consequently did not properly restrict the set of authentication mechanisms that were allowed to be used over an unencrypted connection. This could possibly lead to sending of plain text authentication credentials over an unencrypted connection.