CVE-2019-10182

Related Vulnerabilities: CVE-2019-10182  

Impact: Important Public Date: 2019-07-31 CWE: CWE-22->CWE-94 Bugzilla: 1724958: CVE-2019-10182 icedtea-web: path traversal while processing elements of JNLP files results in arbitrary file overwrite It was found that icedtea-web did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

It was found that icedtea-web did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.

Find out more about CVE-2019-10182 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.2
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Changed
Confidentiality None
Integrity Impact High
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 8 icedtea-web Affected
Red Hat Enterprise Linux 7 icedtea-web Affected
Red Hat Enterprise Linux 6 icedtea-web Out of support scope
Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.

Acknowledgements

Red Hat would like to thank Imre Rad for reporting this issue.