PT-2022-11360 · Oracle+4 · Java+4
Peter Shipton
·
Published
2022-04-27
·
Updated
2025-02-18
·
CVE-2021-41041
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Openj9 versions prior to 0.32.0
Description
The issue arises when Java 8 and 11 fail to throw an exception captured during bytecode verification triggered by a MethodHandle invocation. This allows unverified methods to be invoked using MethodHandles.
Recommendations
For Eclipse Openj9 versions prior to 0.32.0, update to version 0.32.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of MethodHandles to minimize the risk of exploitation.
Fix
Type Confusion
Unchecked Return Value
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Centos
Eclipse Openj9
Java
Red Hat
Suse