CVE-2019-10182

HIGH

Icedtea-web <1.7.2, 1.8.2 - Path Traversal

Title source: llm
STIX 2.1

Description

It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_bugtraq
https://seclists.org/bugtraq/2019/Oct/5
Issue Tracking, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10182
Patch, Third Party Advisory x_refsource_confirm
https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344
Patch, Third Party Advisory x_refsource_confirm
https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html

Scores

CVSS v3 8.2
EPSS 0.0103
EPSS Percentile 77.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L

Details

CWE
CWE-22 CWE-94
Status published
Products (7)
icedtea-web_project/icedtea-web 1.8.2
icedtea-web_project/icedtea-web < 1.7.2
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_server_aus 7.6
redhat/enterprise_linux_server_eus 7.6
redhat/enterprise_linux_workstation 7.0
Published Jul 31, 2019
Tracked Since Feb 18, 2026