REDHAT-BUG-1965497: Medium severity Eclipse Jakarta Expression Language vulnerability
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
References:
https://github.com/eclipse-ee4j/el-ri/issues/155 https://securitylab.github.com/advisories/GHSL-2020-021-jakarta-el/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1965497?
The severity of REDHAT-BUG-1965497 is classified as high due to the potential for invalid EL expressions to be evaluated incorrectly.
How do I fix REDHAT-BUG-1965497?
To fix REDHAT-BUG-1965497, upgrade your Eclipse Jakarta Expression Language to version 3.0.4 or later.
Which versions are affected by REDHAT-BUG-1965497?
Versions of Eclipse Jakarta Expression Language up to and including 3.0.3 are affected by REDHAT-BUG-1965497.
What is the impact of REDHAT-BUG-1965497 on applications?
The impact of REDHAT-BUG-1965497 could lead to security vulnerabilities where attackers may exploit invalid expressions.
Is there a workaround for REDHAT-BUG-1965497?
Currently, there is no confirmed workaround for REDHAT-BUG-1965497; updating to the latest version is recommended.