The HTTP client leaks sensitive information when redirecting to a different domain.
OpenJDK-11 upstream commit: https://github.com/openjdk/jdk11u/commit/ae39653f6db1e1a20ae441446b75d72f16f2fb46 OpenJDK-17 upstream commit: https://github.com/openjdk/jdk17u/commit/770ad1fa038d4df857f4c769580ed27bb5d211e6 OpenJDK-21 upstream commit: https://github.com/openjdk/jdk21u/commit/2494864948c3033fc4ad266fa44b054d1bbb3c7e
This CVE was fixed in Oracle Java 11.0.28, 17.0.16, 21.0.8. https://www.oracle.com/java/technologies/javase/11-0-28-relnotes.html#R11_0_28 https://www.oracle.com/java/technologies/javase/17-0-16-relnotes.html#R17_0_16 https://www.oracle.com/java/technologies/javase/21-0-8-relnotes.html