Improper authorization control for web services In java-1.8.0-openjdk
Description
It was discovered that the Nashorn JavaScript engine in the Scripting component of OpenJDK could allow scripts to access Java APIs even when access to Java APIs was disabled. An untrusted JavaScript executed by Nashorn could use this flaw to bypass intended restrictions.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 1:1.8.0.141-2.b16.el6_9 | ||
rpm rhel7 | 1:1.8.0.141-1.b16.el7_3 |
Aliases
1. 2. 3.