Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31139

Опубликовано: 11 июл. 2022
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
CVSS2: 4.3
EPSS Низкий

Описание

UnsafeAccessor (UA) is a bridge to access jdk.internal.misc.Unsafe & sun.misc.Unsafe. Normally, if UA is loaded as a named module, the internal data of UA is protected by JVM and others can only access UA via UA's standard API. The main application can set up SecurityCheck.AccessLimiter for UA to limit access to UA. Starting with version 1.4.0 and prior to version 1.7.0, when SecurityCheck.AccessLimiter is set up, untrusted code can access UA without limitation, even when UA is loaded as a named module. This issue does not affect those for whom SecurityCheck.AccessLimiter is not set up. Version 1.7.0 contains a patch.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:unsafe_accessor_project:unsafe_accessor:*:*:*:*:*:*:*:*
Версия от 1.4.0 (включая) до 1.7.0 (исключая)

EPSS

Процентиль: 56%
0.00341
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-863

Связанные уязвимости

CVSS3: 5.9
github
больше 3 лет назад

UnsafeAccessor 1.4.0 until 1.7.0 has no security checking for UnsafeAccess.getInstance()

EPSS

Процентиль: 56%
0.00341
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200
CWE-863