Lucene search

K
cvelistEclipseCVELIST:CVE-2021-41041
HistoryApr 27, 2022 - 2:10 a.m.

CVE-2021-41041

2022-04-2702:10:10
CWE-843
CWE-252
CWE-908
eclipse
www.cve.org
7
cve-2021-41041
eclipse openj9
bytecode verification
java 8
java 11
methodhandle invocation
unverified methods

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

33.3%

In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.

CNA Affected

[
  {
    "product": "Eclipse OpenJ9",
    "vendor": "The Eclipse Foundation",
    "versions": [
      {
        "lessThan": "0.32.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

AI Score

5.8

Confidence

High

EPSS

0.001

Percentile

33.3%