Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHBA-2025:1365 - Bug Fix Advisory
Issued:
2025-02-12
Updated:
2025-02-12

RHBA-2025:1365 - Bug Fix Advisory

  • Overview
  • Updated Images

Synopsis

Updated RHEL-9-based OpenJDK container images

Type/Severity

Bug Fix Advisory

Topic

Updated RHEL-9-based OpenJDK container images are now available.

Description

The RHEL-9-based OpenJDK container images have been updated to address security advisories RHSA-2025:1346 and RHSA-2025:1330 (see the References section).

Users of RHEL-9-based OpenJDK container images are advised to upgrade to these updated images, which contain backported patches to correct these security issues, fix these bugs and add these enhancements. Users of these images are also encouraged to rebuild all container images that depend on these images.

You can find images updated by this advisory in the Red Hat Container Catalog (see the References section).

Solution

You can download the RHEL-9-based OpenJDK container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).

Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally.

Affected Products

  • Red Hat JBoss Middleware 1 x86_64

Fixes

  • BZ - 1850004 - CVE-2020-11023 jquery: Untrusted code execution via <option> tag in HTML passed to DOM manipulation methods

CVEs

  • CVE-2020-11023
  • CVE-2024-12797

References

  • https://access.redhat.com/errata/RHSA-2025:1346
  • https://access.redhat.com/errata/RHSA-2025:1330
  • https://access.redhat.com/containers

aarch64

ubi9/openjdk-17@sha256:af9ef77cd6318fa164981aaef04f0a5821beac8ba347ecc0e794634c23619815
ubi9/openjdk-17-runtime@sha256:b2f872cb9863d8b372f08c53866abeb6670683f3ad1083f8ab79bfe6dbeee24c
ubi9/openjdk-21@sha256:69ed72ecd4328d3c11c5c468413079e8492bd3d40378fa0c788d8930471d6cc7
ubi9/openjdk-21-runtime@sha256:fb5a88fa0f2fe231f3d8cc1a8a3caa11db63a9654e7c3a149fac7cf5190e722e

ppc64le

ubi9/openjdk-17@sha256:4a3511334a0c4e990b089b6bddc758658cb8c40cc5a7a85ef5c8633a855228bd
ubi9/openjdk-17-runtime@sha256:9aafdc70b7d432766975e0145aeec37d6cd501bf44061f96e0381eb4344f6698
ubi9/openjdk-21@sha256:00ba0b12e653dee037e0b997745f07aea4397cac7c0edadcd32cb1b6aedd8e1b
ubi9/openjdk-21-runtime@sha256:6b880992d5f7ff7afa7c6d109db7d751047fe2f2727f8e7af1cd3860533494b3

s390x

ubi9/openjdk-17@sha256:ffcdd3f584fb16f57609e2412eaedc6367f6717cdf312e314504d6ab8e577d1d
ubi9/openjdk-17-runtime@sha256:06249b91d756c323c9e7cf0eeefd0c1d8ac4dd5ca5dc5a62d771fa17df38f4d3
ubi9/openjdk-21@sha256:27ec30ac50f5bb9b87f5e6207a7c4ab0177b1df00a78f47fd155eb6f8ea76fb8
ubi9/openjdk-21-runtime@sha256:29081344dad6e8d08c79559e14516f2fb9ea0f25bbb86914db7f8a9d27111fea

x86_64

ubi9/openjdk-17@sha256:3dfa094c0ed518681892d6b98d9c405fef6c4e1f9be260958e3ebf0cdc4249f2
ubi9/openjdk-17-runtime@sha256:aae39d2236641bbcf59080735a8dd7db0647883c0be8800ac2e5912748cbde03
ubi9/openjdk-21@sha256:d4f3f4f465a72b39104df5d4c042a934d4b5620da37ac8e9236c23062548c175
ubi9/openjdk-21-runtime@sha256:ec04e06743f169b3b810dd63fdae7cc3e3c6309eb4c7b4775ea6514d9cffd46d

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility