Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8168862

Tighten permissions granted to the jdk.zipfs module

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: P2
    • Resolution: Fixed
    • Affects Version/s: 9
    • Fix Version/s: 9
    • Component/s: core-libs
    • Labels:
    • Subcomponent:
    • Resolved In Build:
      b145
    • Verification:
      Not verified

      Description

      The jdk.zipfs module is granted permission to read all system properties in lib/security/default.policy. However, from a scan of the code, it appears to only read the "os.name" system property.

      The permissions should be tightened to only grant reading of the specific properties it needs.

        Attachments

          Activity

            People

            Assignee:
            sherman Xueming Shen
            Reporter:
            mullan Sean Mullan
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: