Improper authorization control for web services In java-1.7.0-openjdk
Description
The JGSS component of OpenJDK ignores the value of the javax.security.auth.useSubjectCredsOnly property when using HTTP/SPNEGO authentication and always uses global credentials. It was discovered that this could cause global credentials to be unexpectedly used by an untrusted Java application.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 1:1.7.0.171-2.6.13.0.el6_9 | ||
rpm rhel6 | 1:1.8.0.161-3.b14.el6_9 | ||
rpm rhel7 | 1:1.8.0.161-0.b14.el7_4 | ||
rpm rhel7 | 1:1.7.0.171-2.6.13.0.el7_4 |
Aliases
1. 2. 3.