Improper Privilege Management Affecting openjdk-jre package, versions [,1.8.0_401) [11.0.0,11.0.22) [17.0.0,17.0.10) [21.0.0,21.0.2)
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UPSTREAM-OPENJDKJRE-6164702
- published 17 Jan 2024
- disclosed 16 Jan 2024
- credit Yi Yang
Introduced: 16 Jan 2024
CVE-2024-20918 Open this link in a new tabHow to fix?
Upgrade openjdk-jre
to version 8.0.401, 11.0.22, 17.0.10, 21.0.2 or higher.
Overview
openjdk-jre is a free and open-source implementation of the Java Platform, Standard Edition (Java SE).
Affected versions of this package are vulnerable to Improper Privilege Management in the hotspot/compiler
component.
Note This is only exploitable if the attacker utilizes APIs in the specified component, such as through a web service that provides data to the APIs. Additionally, the vulnerability affects Java deployments that execute untrusted code, relying on the Java sandbox for security.