Lack of data validation In java-1.6.0-ibm
Description
It was found that the HttpURLConnection and HttpsURLConnection classes in the Networking component of OpenJDK failed to check for newline characters embedded in URLs. An attacker able to make a Java application perform an HTTP request using an attacker provided URL could possibly inject additional headers into the request.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | - | - | |
rpm rhel6 | 1:1.8.0.151-1.b12.el6_9 | ||
rpm rhel6 | 1:1.7.0.161-2.6.12.0.el6_9 | ||
rpm rhel7 | 1:1.7.0.161-2.6.12.0.el7_4 | ||
rpm rhel7 | 1:1.8.0.151-1.b12.el7_4 |
Aliases
1. 2. 3.