A vulnerability that allows an attacker to execute arbitrary java code from the javascript engine even though the option "--no-java" was set.
Platform | Package | Release Date | Advisory |
---|---|---|---|
Amazon Linux 2 - Corretto8 Extra | java-1.8.0-amazon-corretto | 2024-01-19 02:20 | ALAS2CORRETTO8-2024-010 |
Amazon Linux 2023 | java-1.8.0-amazon-corretto | 2024-01-19 01:31 | ALAS2023-2024-486 |
Amazon Linux 2 - Core | java-1.8.0-openjdk | 2024-02-01 19:57 | ALAS2-2024-2438 |
Amazon Linux 2 - Core | java-11-amazon-corretto | 2024-01-17 00:55 | ALAS2-2024-2414 |
Amazon Linux 2023 | java-11-amazon-corretto | 2024-01-17 00:44 | ALAS2023-2024-484 |
Amazon Linux 2 - Java-openjdk11 Extra | java-11-openjdk | 2024-02-01 20:10 | ALAS2JAVA-OPENJDK11-2024-007 |
Amazon Linux 2 - Core | java-17-amazon-corretto | 2024-01-17 00:55 | ALAS2-2024-2415 |
Amazon Linux 2023 | java-17-amazon-corretto | 2024-01-17 00:44 | ALAS2023-2024-483 |
Amazon Linux 2023 | java-21-amazon-corretto | 2024-01-17 00:44 | ALAS2023-2024-485 |
Score Type | Score | Vector | |
---|---|---|---|
Amazon Linux | CVSSv3 | 7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
NVD | CVSSv3 | 7.4 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |