CVE-2024-20918

Public on 2024-01-16
Modified on 2024-01-31
Description
A vulnerability that allows an attacker to execute arbitrary java code from the javascript engine even though the option "--no-java" was set.
Severity
Important severity
Important
CVSS v3 Base Score
7.4
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Corretto8 Extra java-1.8.0-amazon-corretto 2024-01-19 ALAS2CORRETTO8-2024-010 Fixed
Amazon Linux 2023 java-1.8.0-amazon-corretto 2024-01-19 ALAS2023-2024-486 Fixed
Amazon Linux 1 java-1.8.0-openjdk No Fix Planned
Amazon Linux 2 - Core java-1.8.0-openjdk 2024-02-01 ALAS2-2024-2438 Fixed
Amazon Linux 2 - Core java-11-amazon-corretto 2024-01-17 ALAS2-2024-2414 Fixed
Amazon Linux 2023 java-11-amazon-corretto 2024-01-17 ALAS2023-2024-484 Fixed
Amazon Linux 2 - Java-openjdk11 Extra java-11-openjdk 2024-02-01 ALAS2JAVA-OPENJDK11-2024-007 Fixed
Amazon Linux 2 - Core java-17-amazon-corretto 2024-01-17 ALAS2-2024-2415 Fixed
Amazon Linux 2023 java-17-amazon-corretto 2024-01-17 ALAS2023-2024-483 Fixed
Amazon Linux 2023 java-21-amazon-corretto 2024-01-17 ALAS2023-2024-485 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
NVD CVSSv3 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N