It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
2019-07-31T22:15:12.183
2024-11-21T04:18:36.017
Modified
CVSSv3.0: 8.2 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | icedtea-web_project | icedtea-web | ≤ 1.7.2 | Yes |
Application | icedtea-web_project | icedtea-web | 1.8.2 | Yes |
Operating System | redhat | enterprise_linux_desktop | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server | 7.0 | Yes |
Operating System | redhat | enterprise_linux_server_aus | 7.6 | Yes |
Operating System | redhat | enterprise_linux_server_eus | 7.6 | Yes |
Operating System | redhat | enterprise_linux_workstation | 7.0 | Yes |