Bug 1730255 (CVE-2019-2786) - CVE-2019-2786 OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381)
Summary: CVE-2019-2786 OpenJDK: Insufficient restriction of privileges in AccessContro...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2019-2786
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1724467 1724468 1724469 1724470 1724471 1724472 1724473 1724474 1724475 1724476 1724477 1724478 1731477 1731478 1731479 1741809 1741810 1741811 1741812 1741813 1745502
Blocks: 1724463
TreeView+ depends on / blocked
 
Reported: 2019-07-16 10:13 UTC by Tomas Hoger
Modified: 2019-10-02 08:47 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-08-26 13:07:23 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:1810 0 None None None 2019-07-22 12:40:26 UTC
Red Hat Product Errata RHSA-2019:1811 0 None None None 2019-07-22 12:40:38 UTC
Red Hat Product Errata RHSA-2019:1815 0 None None None 2019-07-22 12:40:49 UTC
Red Hat Product Errata RHSA-2019:1816 0 None None None 2019-07-22 12:41:02 UTC
Red Hat Product Errata RHSA-2019:1817 0 None None None 2019-07-22 12:40:05 UTC
Red Hat Product Errata RHSA-2019:1839 0 None None None 2019-07-23 17:55:22 UTC
Red Hat Product Errata RHSA-2019:1840 0 None None None 2019-07-23 16:15:43 UTC
Red Hat Product Errata RHSA-2019:2585 0 None None None 2019-09-02 07:18:13 UTC
Red Hat Product Errata RHSA-2019:2590 0 None None None 2019-09-02 07:44:59 UTC
Red Hat Product Errata RHSA-2019:2592 0 None None None 2019-09-02 10:34:47 UTC
Red Hat Product Errata RHSA-2019:2737 0 None None None 2019-09-11 15:07:15 UTC

Description Tomas Hoger 2019-07-16 10:13:11 UTC
It was discovered that the AccessController class implementation in the Security component of OpenJDK failed, in certain cases, to consider the current context and correctly restrict privileges based on it.  An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions.

Comment 1 Tomas Hoger 2019-07-16 20:56:20 UTC
Public now via Oracle CPU July 2019:

https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html#AppendixJAVA

Fixed in Oracle Java SE 12.0.2, 11.0.4, and 8u221.

Comment 2 errata-xmlrpc 2019-07-22 12:40:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:1817 https://access.redhat.com/errata/RHSA-2019:1817

Comment 3 errata-xmlrpc 2019-07-22 12:40:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1810 https://access.redhat.com/errata/RHSA-2019:1810

Comment 4 errata-xmlrpc 2019-07-22 12:40:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:1811 https://access.redhat.com/errata/RHSA-2019:1811

Comment 5 errata-xmlrpc 2019-07-22 12:40:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1815 https://access.redhat.com/errata/RHSA-2019:1815

Comment 6 errata-xmlrpc 2019-07-22 12:41:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:1816 https://access.redhat.com/errata/RHSA-2019:1816

Comment 7 errata-xmlrpc 2019-07-23 16:15:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2019:1840 https://access.redhat.com/errata/RHSA-2019:1840

Comment 8 errata-xmlrpc 2019-07-23 17:55:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:1839 https://access.redhat.com/errata/RHSA-2019:1839

Comment 9 Product Security DevOps Team 2019-08-26 13:07:23 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2019-2786

Comment 10 errata-xmlrpc 2019-09-02 07:18:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Supplementary

Via RHSA-2019:2585 https://access.redhat.com/errata/RHSA-2019:2585

Comment 11 errata-xmlrpc 2019-09-02 07:44:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2019:2590 https://access.redhat.com/errata/RHSA-2019:2590

Comment 12 errata-xmlrpc 2019-09-02 10:34:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2019:2592 https://access.redhat.com/errata/RHSA-2019:2592

Comment 13 errata-xmlrpc 2019-09-11 15:07:13 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 5.8

Via RHSA-2019:2737 https://access.redhat.com/errata/RHSA-2019:2737


Note You need to log in before you can comment on or make changes to this bug.