CVE-2024-20954

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-20954
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-20954.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-20954
Published
2024-04-16T22:15:11Z
Modified
2025-01-15T05:05:15.426892Z
Downstream
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Compiler). Supported versions that are affected are Oracle GraalVM for JDK: 17.0.10, 21.0.2, 22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

References

Affected packages

Git / github.com/graalvm/graalvm-ce-builds

Affected ranges

Type
GIT
Repo
https://github.com/graalvm/graalvm-ce-builds
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

graal-23.*

graal-23.0.0
graal-23.0.1
graal-23.0.2

jdk-17.*

jdk-17.0.7
jdk-17.0.8
jdk-17.0.9

jdk-20.*

jdk-20.0.1
jdk-20.0.2

jdk-21.*

jdk-21.0.0
jdk-21.0.1
jdk-21.0.2

jdk-22.*

jdk-22.0.0
jdk-22.0.1
jdk-22.0.2

jdk-23.*

jdk-23.0.0
jdk-23.0.1

vm-19.*

vm-19.3.0
vm-19.3.0.2
vm-19.3.1
vm-19.3.2
vm-19.3.2-pre
vm-19.3.3
vm-19.3.4
vm-19.3.5
vm-19.3.6

vm-20.*

vm-20.0.0
vm-20.0.1
vm-20.1.0
vm-20.2.0
vm-20.3.0
vm-20.3.1
vm-20.3.1.2
vm-20.3.2
vm-20.3.3
vm-20.3.4
vm-20.3.5
vm-20.3.6

vm-21.*

vm-21.0.0
vm-21.0.0.2
vm-21.1.0
vm-21.2.0
vm-21.3.0
vm-21.3.1
vm-21.3.2
vm-21.3.3
vm-21.3.3.1

vm-22.*

vm-22.0.0.2
vm-22.1.0
vm-22.2.0
vm-22.3.0
vm-22.3.1
vm-22.3.2
vm-22.3.3

vm-ce-21.*

vm-ce-21.2.0

vm-ce-22.*

vm-ce-22.3.3