Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.openjfx/javafx-media
  4. ›
  5. CVE-2024-20925

CVE-2024-20925: Vulnerability affecting the org.openjfx:javafx-media maven component of the OpenJFX project

February 17, 2024 (updated November 4, 2025)

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u391; Oracle GraalVM Enterprise Edition: 20.3.12 and 21.3.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).

References

  • github.com/advisories/GHSA-47g3-mf24-6559
  • github.com/openjdk/jfx
  • github.com/openjdk/jfx/blob/4beeb89f864ccf1424db36c9739a7f6999adeecc/doc-files/release-notes-22.md?plain=1
  • github.com/openjdk/jfx/commit/0a52a4cf1d1226e7a3c6d73313fde02e7f36fb11
  • github.com/openjdk/jfx17u/commit/18206453163dec04f36f8787ce73624bb9ba6a7d
  • github.com/openjdk/jfx21u/commit/0c00753da13ed696b1a5025ce01ff478ee7ebd0a
  • nvd.nist.gov/vuln/detail/CVE-2024-20925
  • openjdk.org/groups/vulnerability/advisories/2024-01-16
  • security.netapp.com/advisory/ntap-20240201-0002
  • www.oracle.com/security-alerts/cpujan2024.html

Code Behaviors & Features

Detect and mitigate CVE-2024-20925 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 17.0.10, all versions starting from 18 before 21.0.2

Fixed versions

  • 17.0.10
  • 21.0.2

Solution

Upgrade to versions 17.0.10, 21.0.2 or above.

Impact 3.1 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Learn more about CVSS

Source file

maven/org.openjfx/javafx-media/CVE-2024-20925.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 07 Dec 2025 12:18:45 +0000.