Server side template injection In java-1.8.0-openjdk
Description
It was discovered that the I18n component of OpenJDK could use an untrusted search path when loading resource bundle classes. A local attacker could possibly use this flaw to execute arbitrary code as another local user by making their Java application load an attacker controlled class file.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel6 | 1:1.8.0.161-3.b14.el6_9 | ||
rpm rhel7 | 1:1.7.0.171-2.6.13.0.el7_4 | ||
rpm rhel6 | 1:1.7.0.171-2.6.13.0.el6_9 | ||
rpm rhel7 | 1:1.8.0.161-0.b14.el7_4 | ||
rpm rhel6 | - | - |
Aliases
1. 2. 3.