File _patchinfo of Package patchinfo.41467

<patchinfo incident="41467">
  <issue tracker="cve" id="2025-53057"/>
  <issue tracker="cve" id="2025-53066"/>
  <issue tracker="bnc" id="1252414">VUL-0: CVE-2025-53057: java-17-openjdk, java-21-openjdk: unauthenticated attacker can achieve unauthorized creation, deletion or modification access to critical data</issue>
  <issue tracker="bnc" id="1252417">VUL-0: CVE-2025-53066: java-17-openjdk, java-21-openjdk: unauthenticated attacker can achive unauthorized access to critical data or complete access</issue>
  <packager>fstrba</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for java-1_8_0-openjdk</summary>
  <description>This update for java-1_8_0-openjdk fixes the following issues:

Update to version jdk8u472 (icedtea-3.37.0):
  
-  CVE-2025-53057: Fixed certificate handling leading to unauthorized creation, deletion or modification access to critical data (bsc#1252414)
-  CVE-2025-53066: Fixed Path factories leading to unauthorized access to critical data or complete access (bsc#1252417)
  </description>
</patchinfo>
openSUSE Build Service is sponsored by