CVE-2023-2597: Eclipse OPENJ9
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.
Affected products
- Eclipse OPENJ9: before 0.38.0 (fixed in 0.38.0)
Published 2023-05-22. Last modified 2026-06-17.