CVE-2021-41041
java-11-openj9,java-1_8_0-openj9: unverified methods can be invoked using MethodHandles
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
En Eclipse Openj9 versiones anteriores a 0.32.0, Java 8 y 11 no lanzan la excepción capturada durante la verificación del código de bytes cuando la verificación es desencadenada por una invocación de MethodHandle, permitiendo invocar métodos no verificados mediante MethodHandles
An update that fixes 9 vulnerabilities is now available. This update for java-1_8_0-openj9 fixes the following issues. Fixed an integer truncation issue in the Xalan Java XSLT library that occurred when processing malicious stylesheets. Fixed a potential bypass of sandbox restrictions in the Hotspot component. Fixed a potential bypass of sandbox restrictions in the Hotspot component. Failed an issue that could allow unverified methods to be invoked using MethodHandles. Fixed a remote partial denial of service issue. Fixed an issue that could allow a remote attacker to update, insert or delete data. Fixed a remote partial denial of service issue. Fixed an issue that could allow unauthorized access to confidential data. Fixed an issue that could allow a remote attacker to update, insert or delete data.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-13 CVE Reserved
- 2022-04-27 CVE Published
- 2024-08-04 CVE Updated
- 2025-05-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-252: Unchecked Return Value
- CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
- CWE-908: Use of Uninitialized Resource
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=579744 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/eclipse-openj9/openj9/pull/14935 | 2022-05-05 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-41041 | 2022-08-02 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2080954 | 2022-08-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Eclipse Search vendor "Eclipse" | Openj9 Search vendor "Eclipse" for product "Openj9" | < 0.32.0 Search vendor "Eclipse" for product "Openj9" and version " < 0.32.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Java Se Search vendor "Oracle" for product "Java Se" | 8 Search vendor "Oracle" for product "Java Se" and version "8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Java Se Search vendor "Oracle" for product "Java Se" | 11 Search vendor "Oracle" for product "Java Se" and version "11" | - |
Affected
|