Improper Handling
Affecting openjdk-jre package, versions [1.7.0, 1.7.0_231) || [1.8.0, 1.8.0_221) || [11.0.0, 11.0.5) || [13.0.0, 13.0.1)
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
openjdk-jre is a free and open-source implementation of the Java Platform, Standard Edition (Java SE).
Affected versions of this package are vulnerable to Improper Handling. The Kerberos implementation in the Kerberos component in OpenJDK did not properly handle proxy credentials. This could lead to the unintended use of wrong credentials and possible user impersonation.
Remediation
Upgrade openjdk-jre
to version 7.0.231, 8.0.221, 11.0.5, 13.0.1 or higher.
References
CVSS Score
5.6
medium severity
-
Attack VectorNetwork
-
Attack ComplexityHigh
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityLow
-
IntegrityLow
-
AvailabilityLow
- Credit
- Unknown
- CVE
- CVE-2019-2949
- CWE
- CWE-229
- Snyk ID
- SNYK-UPSTREAM-OPENJDKJRE-473430
- Disclosed
- 16 Oct, 2019
- Published
- 16 Oct, 2019