CVE-2024-10917: Eclipse OPENJ9

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.

Affected products

  • Eclipse OPENJ9: from 0.8.0, before 0.48.0 (fixed in 0.48.0)

Published 2024-11-11. Last modified 2026-06-17.