The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
CVSS Details
- CVSS 3.1 Base Score: 8.2
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Dec 1, 2016 | Apr 29, 2013 |
| Debian | — | Upgrade icedtea-web | Jul 30, 2024 | Apr 29, 2013 |
| Oracle_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadoc | Oct 16, 2024 | Apr 29, 2013 |
| Suse | — | Upgrade icedtea-web-debuginfoUpgrade icedtea-web-javadocUpgrade icedtea-web-debugsourceUpgrade icedtea-web | Feb 17, 2015 | Apr 29, 2013 |
| Ubuntu | — | Upgrade icedtea-netx | Nov 8, 2024 | Apr 29, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub