Skip to content

Commit

Permalink
Update CHANGELOG.md with CVE
Browse files Browse the repository at this point in the history
  • Loading branch information
alvdavi committed Apr 9, 2020
1 parent aca810a commit 055a9a1
Showing 1 changed file with 21 additions and 3 deletions.
24 changes: 21 additions & 3 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ The following sections describe the changes for each release of Amazon Corretto

## April 2020 critical patch update: Corretto version 11.0.7.10.1

Release Date: Jan 23, 2020
Release Date: April 14, 2020

**Target Platforms**
+ RPM-based Linux using glibc 2.12 or later, x86_64
Expand All @@ -14,8 +14,7 @@ Release Date: Jan 23, 2020
+ Windows 7 or later, x86_64
+ macOS 10.13 and later, x86_64

The following issues and enhancements are addressed in 11.0.6.10.1.

The following issues and enhancements are addressed in 11.0.7.10.1.

| Issue Name | Platform | Description | Link |
| --- | --- | --- | --- |
Expand All @@ -25,6 +24,25 @@ The following issues and enhancements are addressed in 11.0.6.10.1.
| Add support for test image on linux | Linux | Build process generates additional artifacts to support native jtreg tests | |
| Add support for test image on macOS | macOS | Build process generates additional artifacts to support native jtreg tests | |

The following CVE are addressed in 11.0.7.10.1.

| CVE | CVSS | Component |
| --- | --- | --- |
| CVE-2020-2803 | 8.3 | core-libs/java.nio |
| CVE-2020-2805 | 8.3 | core-libs/java.io |
| CVE-2020-2816 | 7.5 | security-libs/javax.net.ssl |
| CVE-2020-2781 | 5.3 | security-libs/java.security |
| CVE-2020-2830 | 5.3 | core-libs/java.util |
| CVE-2020-2767 | 4.8 | security-libs/javax.net.ssl |
| CVE-2020-2800 | 4.8 | core-libs/java.net |
| CVE-2020-2778 | 3.7 | security-libs/javax.net.ssl |
| CVE-2020-2754 | 3.7 | core-libs/javax.script |
| CVE-2020-2755 | 3.7 | core-libs/javax.script |
| CVE-2020-2773 | 3.7 | security-libs/javax.xml.crypto |
| CVE-2020-2756 | 3.7 | core-libs/java.io:serialization |
| CVE-2020-2757 | 3.7 | core-libs/java.io:serialization |


## Corretto version: 11.0.6.10.1-2 (macOS)

Release Date: Jan 23, 2020
Expand Down

0 comments on commit 055a9a1

Please sign in to comment.