1. 내용
범위 확인 제거 중 잘못된 비교 문제(Hotspot, 8264066) (CVE-2021-2388)
FTP PASV 명령 응답으로 인해 FtpClient가 임의의 호스트에 연결할 수 있는 문제 (Networking, 8258432) (CVE-2021-2341)
여러 MANIFEST.MF 파일이 있는 JAR 파일의 잘못된 확인 (Library, 8260967) (CVE-2021-2369)
2. 업데이트 방법
yum update java
3. 관련 패키지
java-1.8.0-openjdk-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-accessibility-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-accessibility-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-debuginfo-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-demo-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-demo-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-devel-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-devel-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-headless-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-headless-1.8.0.302.b08-0.el7_9.x86_64.rpm
java-1.8.0-openjdk-javadoc-1.8.0.302.b08-0.el7_9.noarch.rpm
java-1.8.0-openjdk-javadoc-zip-1.8.0.302.b08-0.el7_9.noarch.rpm
java-1.8.0-openjdk-src-1.8.0.302.b08-0.el7_9.i686.rpm
java-1.8.0-openjdk-src-1.8.0.302.b08-0.el7_9.x86_64.rpm
4. CVE-ID
CVE-2021-2388
CVE-2021-2341
CVE-2021-2369
5. 참고
https://access.redhat.com/errata/RHSA-2021:2845