Bug 1730099 (CVE-2019-2816)

Summary: CVE-2019-2816 OpenJDK: Missing URL format validation (Networking, 8221518)
Product: [Other] Security Response Reporter: Tomas Hoger <thoger>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: ahughes, bkearney, dbhole, java-qa, jvanek, security-response-team, tlestach, yozone
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-26 13:07:21 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1724467, 1724468, 1724469, 1724470, 1724471, 1724472, 1724473, 1724474, 1724475, 1724476, 1724477, 1724478, 1731477, 1731478, 1731479, 1738535, 1738536, 1738537, 1741809, 1741810, 1741811, 1741812, 1741813, 1745502    
Bug Blocks: 1724463    

Description Tomas Hoger 2019-07-15 20:15:03 UTC
An input validation flaw was found in the URL class implementation in the Networking component of OpenJDK.  A URL class instance could have been created for a URL string containing invalid characters not permitted in URLs.

Comment 1 Tomas Hoger 2019-07-16 20:48:17 UTC
Public now via Oracle CPU July 2019:

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA

Fixed in Oracle Java SE 12.0.2, 11.0.4, 8u221, and 7u231.

Comment 2 errata-xmlrpc 2019-07-22 12:40:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:1817 https://access.redhat.com/errata/RHSA-2019:1817

Comment 3 errata-xmlrpc 2019-07-22 12:40:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1810 https://access.redhat.com/errata/RHSA-2019:1810

Comment 4 errata-xmlrpc 2019-07-22 12:40:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:1811 https://access.redhat.com/errata/RHSA-2019:1811

Comment 5 errata-xmlrpc 2019-07-22 12:40:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1815 https://access.redhat.com/errata/RHSA-2019:1815

Comment 6 errata-xmlrpc 2019-07-22 12:40:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:1816 https://access.redhat.com/errata/RHSA-2019:1816

Comment 7 errata-xmlrpc 2019-07-23 16:15:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:1840 https://access.redhat.com/errata/RHSA-2019:1840

Comment 8 errata-xmlrpc 2019-07-23 17:55:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1839 https://access.redhat.com/errata/RHSA-2019:1839

Comment 9 errata-xmlrpc 2019-08-15 09:01:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2019:2495 https://access.redhat.com/errata/RHSA-2019:2495

Comment 10 errata-xmlrpc 2019-08-15 09:03:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2019:2494 https://access.redhat.com/errata/RHSA-2019:2494

Comment 11 Product Security DevOps Team 2019-08-26 13:07:21 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-2816

Comment 12 errata-xmlrpc 2019-09-02 07:18:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2019:2585 https://access.redhat.com/errata/RHSA-2019:2585

Comment 13 errata-xmlrpc 2019-09-02 07:44:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:2590 https://access.redhat.com/errata/RHSA-2019:2590

Comment 14 errata-xmlrpc 2019-09-02 10:34:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2019:2592 https://access.redhat.com/errata/RHSA-2019:2592

Comment 15 errata-xmlrpc 2019-09-11 15:07:13 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 5.8

Via RHSA-2019:2737 https://access.redhat.com/errata/RHSA-2019:2737