Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10185

Опубликовано: 31 июл. 2019
Источник: nvd
CVSS3: 8.2
CVSS3: 8.6
CVSS2: 6.4
EPSS Низкий

Описание

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*
Версия до 1.7.2 (включая)
cpe:2.3:a:icedtea-web_project:icedtea-web:1.8.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Конфигурация 3
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01563
Низкий

8.2 High

CVSS3

8.6 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.2
redhat
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.6
debian
больше 6 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was ...

CVSS3: 8.6
github
больше 3 лет назад

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.

CVSS3: 8.6
fstec
больше 6 лет назад

Уязвимость плагина IcedTea-Web, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю записать произвольные файлы в файловую систему устройства

EPSS

Процентиль: 81%
0.01563
Низкий

8.2 High

CVSS3

8.6 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-22
CWE-22