Bug 2041435 (CVE-2022-21282) - CVE-2022-21282 OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (JAXP, 8270492)
Summary: CVE-2022-21282 OpenJDK: Insufficient URI checks in the XSLT TransformerImpl (...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2022-21282
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2039391 2039393 2039394 2039396 2039397 2039588 2040423 2040424 2040425 2040433 2040434 2040435 2040813 2040817
Blocks: 2039369
TreeView+ depends on / blocked
 
Reported: 2022-01-17 10:58 UTC by Tomas Hoger
Modified: 2022-04-25 15:04 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2022-01-27 20:32:44 UTC


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2022:1527 0 None None None 2022-04-25 15:04:31 UTC
Red Hat Product Errata RHSA-2022:0161 0 None None None 2022-01-19 09:12:32 UTC
Red Hat Product Errata RHSA-2022:0165 0 None None None 2022-01-24 11:40:29 UTC
Red Hat Product Errata RHSA-2022:0166 0 None None None 2022-01-24 11:39:26 UTC
Red Hat Product Errata RHSA-2022:0185 0 None Waiting on Customer Egress-IP issue coming back to the cluster 2022-05-27 21:29:44 UTC
Red Hat Product Errata RHSA-2022:0204 0 None None None 2022-01-24 10:10:59 UTC
Red Hat Product Errata RHSA-2022:0209 0 None None None 2022-01-24 09:42:02 UTC
Red Hat Product Errata RHSA-2022:0211 0 None None None 2022-01-24 09:46:31 UTC
Red Hat Product Errata RHSA-2022:0228 0 None None None 2022-01-24 13:03:12 UTC
Red Hat Product Errata RHSA-2022:0229 0 None None None 2022-01-24 13:04:15 UTC
Red Hat Product Errata RHSA-2022:0233 0 None None None 2022-01-24 09:38:59 UTC
Red Hat Product Errata RHSA-2022:0304 0 None None None 2022-01-27 14:05:44 UTC
Red Hat Product Errata RHSA-2022:0305 0 None None None 2022-01-27 14:10:45 UTC
Red Hat Product Errata RHSA-2022:0306 0 None None None 2022-01-27 15:15:39 UTC
Red Hat Product Errata RHSA-2022:0307 0 None None None 2022-01-27 14:17:11 UTC
Red Hat Product Errata RHSA-2022:0312 0 None None None 2022-01-27 16:14:13 UTC
Red Hat Product Errata RHSA-2022:0317 0 None None None 2022-01-27 20:02:11 UTC
Red Hat Product Errata RHSA-2022:0321 0 None None None 2022-01-27 20:00:40 UTC

Description Tomas Hoger 2022-01-17 10:58:55 UTC
It was discovered that the TransformerImpl class implementation in the JAXP component of OpenJDK did not properly check access restrictions when performing URI resolution. This could possibly lead to information disclosure when performing XSLT transformations.

Comment 1 Tomas Hoger 2022-01-18 21:31:19 UTC
Public now via Oracle CPU January 2022:

https://www.oracle.com/security-alerts/cpujan2022.html#AppendixJAVA

Fixed in Oracle Java SE 17.0.2, 11.0.14, 8u321, and 7u331.

Comment 2 errata-xmlrpc 2022-01-19 09:12:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0161 https://access.redhat.com/errata/RHSA-2022:0161

Comment 7 errata-xmlrpc 2022-01-24 09:38:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:0233 https://access.redhat.com/errata/RHSA-2022:0233

Comment 8 errata-xmlrpc 2022-01-24 09:41:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:0209 https://access.redhat.com/errata/RHSA-2022:0209

Comment 9 errata-xmlrpc 2022-01-24 09:44:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0185 https://access.redhat.com/errata/RHSA-2022:0185

Comment 10 errata-xmlrpc 2022-01-24 09:46:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:0211 https://access.redhat.com/errata/RHSA-2022:0211

Comment 11 errata-xmlrpc 2022-01-24 10:10:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:0204 https://access.redhat.com/errata/RHSA-2022:0204

Comment 12 errata-xmlrpc 2022-01-24 11:39:23 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.2

Via RHSA-2022:0166 https://access.redhat.com/errata/RHSA-2022:0166

Comment 13 errata-xmlrpc 2022-01-24 11:40:27 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 17.0.2

Via RHSA-2022:0165 https://access.redhat.com/errata/RHSA-2022:0165

Comment 14 errata-xmlrpc 2022-01-24 13:03:09 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.14

Via RHSA-2022:0228 https://access.redhat.com/errata/RHSA-2022:0228

Comment 15 errata-xmlrpc 2022-01-24 13:04:13 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 11.0.14

Via RHSA-2022:0229 https://access.redhat.com/errata/RHSA-2022:0229

Comment 19 errata-xmlrpc 2022-01-27 14:05:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions

Via RHSA-2022:0304 https://access.redhat.com/errata/RHSA-2022:0304

Comment 20 errata-xmlrpc 2022-01-27 14:10:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Extended Update Support

Via RHSA-2022:0305 https://access.redhat.com/errata/RHSA-2022:0305

Comment 21 errata-xmlrpc 2022-01-27 14:17:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:0307 https://access.redhat.com/errata/RHSA-2022:0307

Comment 22 errata-xmlrpc 2022-01-27 15:15:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2022:0306 https://access.redhat.com/errata/RHSA-2022:0306

Comment 23 errata-xmlrpc 2022-01-27 16:14:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Extended Update Support

Via RHSA-2022:0312 https://access.redhat.com/errata/RHSA-2022:0312

Comment 24 errata-xmlrpc 2022-01-27 20:00:38 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u322

Via RHSA-2022:0321 https://access.redhat.com/errata/RHSA-2022:0321

Comment 25 errata-xmlrpc 2022-01-27 20:02:09 UTC
This issue has been addressed in the following products:

  Red Hat Build of OpenJDK 8u322

Via RHSA-2022:0317 https://access.redhat.com/errata/RHSA-2022:0317

Comment 26 Product Security DevOps Team 2022-01-27 20:32:42 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-21282


Note You need to log in before you can comment on or make changes to this bug.