vulnerability

Huawei EulerOS: CVE-2017-10295: java-1.7.0-openjdk security update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Oct 19, 2017
Added
Nov 30, 2017
Modified
Apr 25, 2025

Description

It was found that the HttpURLConnection and HttpsURLConnection classes in the Networking component of OpenJDK failed to check for newline characters embedded in URLs. An attacker able to make a Java application perform an HTTP request using an attacker provided URL could possibly inject additional headers into the request.

Solutions

huawei-euleros-2_0_sp1-upgrade-java-1.7.0-openjdkhuawei-euleros-2_0_sp1-upgrade-java-1.7.0-openjdk-develhuawei-euleros-2_0_sp1-upgrade-java-1.7.0-openjdk-headless
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.