VDB

GCVE-VVD-MAGEIA-2023-272

GCVE-VVD-MAGEIA-2023-272
Advisory Published
Vulnetix · Advisory published September 30, 2023
The updated packages fix security vulnerabilities and a file conflict : Improper connection handling during TLS handshake. (CVE-2023-21930) Incorrect enqueue of references in garbage collector. (CVE-2023-21954) Certificate validation issue in TLS session negotiation. (CVE-2023-21967) Swing HTML parsing issue. (CVE-2023-21939) Incorrect handling of NULL characters in ProcessBuilder. (CVE-2023-21938) Missing string checks for NULL characters. (CVE-2023-21937) Missing check for slash characters in URI-to-path conversion. (CVE-2023-21968) Array indexing integer overflow issue. (CVE-2023-22045) Improper handling of slash characters in URI-to-path conversion. (CVE-2023-22049) O(n^2) growth via consecutive marks. (CVE-2023-25193) HTTP client insufficient file name validation. (CVE-2023-22006) ZIP file parsing infinite loop. (CVE-2023-22036) Modulo operator array indexing issue. (CVE-2023-22044) Weakness in AES implementation. (CVE-2023-22041)

Affected Products

VendorProductVersionsPlatforms
Mageiajava-1.8.0-openjdk0 (affected), 1.8.0.382.b05-1.mga8 (unaffected)
Mageiajava-11-openjdk0 (affected), 11.0.20.0.8-1.mga8 (unaffected)
Mageiaopenjfx0 (affected), 11.0.9.2-4.mga8 (unaffected)
Mageiajava-1.8.0-openjdk0 (affected), 1.8.0.382.b05-1.mga9 (unaffected)
Mageiajava-11-openjdk0 (affected), 11.0.20.0.8-1.mga9 (unaffected)
Mageiajava-17-openjdk0 (affected), 17.0.8.0.7-1.mga9 (unaffected)
Mageiajava-latest-openjdk0 (affected), 20.0.2.0.9-1.rolling.2.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›