Bug 2027791 (CVE-2021-41035)
Summary: | CVE-2021-41035 IBM JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | unspecified | CC: | java-qa |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-02-01 16:01:41 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 2026908, 2026909, 2026910, 2026911, 2061507, 2070466 | ||
Bug Blocks: | 2011827 |
Description
Tomas Hoger
2021-11-30 16:39:54 UTC
IBM has not published their full CVSS vector yet, only the CVSS score of 5.3. Eclipse Foundation's CVE request issue does include any CVSS score or impact rating form the OpenJ9 upstream: https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104 In reply to comment #1: > IBM has not published their full CVSS vector yet, only the CVSS score of 5.3. IBM CVSS score is now available via their security bulletin: https://www.ibm.com/support/pages/node/6522860 which notes: CVEID: CVE-2021-41035 DESCRIPTION: Eclipse Openj9 could provide weaker than expected security, caused by the failure to throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. An attacker could exploit this vulnerability to launch further attacks on the system. CVSS Base score: 5.3 CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2021:5030 https://access.redhat.com/errata/RHSA-2021:5030 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Supplementary Via RHSA-2022:0310 https://access.redhat.com/errata/RHSA-2022:0310 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2022:0345 https://access.redhat.com/errata/RHSA-2022:0345 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-41035 |