Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20914
HistoryJul 29, 2019 - 12:08 a.m.

Information Disclosure

2019-07-2900:08:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

0.002 Low

EPSS

Percentile

61.6%

openjdk is vulnerable to information disclosure. A flaw was found in the way the JSSE component of OpenJDK handled certificate status / OCSP stapling message during TLS handshake. A remote attacker could possibly use this flaw to gain access to certain sensitive information by manipulating TLS handshake messages.