Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10181

Опубликовано: 31 июл. 2019
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

It was found that executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6icedtea-webOut of support scope
Red Hat Enterprise Linux 7icedtea-webFixedRHSA-2019:200331.07.2019
Red Hat Enterprise Linux 8icedtea-webFixedRHSA-2019:200431.07.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=1725928icedtea-web: unsigned code injection in a signed JAR file

EPSS

Процентиль: 44%
0.00217
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 6 лет назад

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVSS3: 8.1
nvd
больше 6 лет назад

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVSS3: 8.1
debian
больше 6 лет назад

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 e ...

CVSS3: 8.1
github
больше 3 лет назад

It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

CVSS3: 8.1
fstec
больше 6 лет назад

Уязвимость плагина IcedTea-Web, связанная с недостаточной проверкой подлинности данных, позволяющая нарушителю внедрить произвольный код в JAR-файл

EPSS

Процентиль: 44%
0.00217
Низкий

6.3 Medium

CVSS3