UnsafeAccessor 1.4.0 until 1.7.0 has no security checking for UnsafeAccess.getInstance()
Moderate severity
GitHub Reviewed
Published
Jul 11, 2022
in
Karlatemp/UnsafeAccessor
•
Updated Jul 24, 2023
Package
Affected versions
>= 1.4.0, < 1.7.0
Patched versions
1.7.0
Description
Published by the National Vulnerability Database
Jul 11, 2022
Published to the GitHub Advisory Database
Jul 12, 2022
Reviewed
Jul 12, 2022
Last updated
Jul 24, 2023
Overview
Affected versions have no limit to using unsafe-accessor. Can be ignored if
SecurityCheck.AccessLimiter
not setupDetails
If UA was loaded as a named module, the internal data of UA will be protected by JVM and others can only access UA via UA's standard api.
Main application can setup
SecurityCheck.AccessLimiter
for UA to limit accesses to UA.Untrusted code can access UA without lmitation in affected versions even UA was loaded as a named module.
References
The commit to fix
References