Vulnerability Description
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Openj9 | < 0.29.0 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395Vendor Advisory
- https://github.com/eclipse-openj9/openj9/pull/13740PatchThird Party Advisory
- https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104Vendor Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=576395Vendor Advisory
- https://github.com/eclipse-openj9/openj9/pull/13740PatchThird Party Advisory
- https://gitlab.eclipse.org/eclipsefdn/emo-team/emo/-/issues/104Vendor Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
FAQ
What is CVE-2021-41035?
CVE-2021-41035 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
How severe is CVE-2021-41035?
CVE-2021-41035 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-41035?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Openj9.