It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | No Centos packages or updates have been released to address this issue | Aug 28, 2019 | Jul 31, 2019 |
| Debian | — | Upgrade icedtea-web | Sep 11, 2019 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade icedtea-web | Sep 12, 2019 | Jul 31, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade icedtea-web | Aug 31, 2020 | Jul 31, 2019 |
| Oracle_linux | — | Upgrade icedtea-web-javadocUpgrade icedtea-webUpgrade icedtea-web-devel | Jul 21, 2020 | Jul 31, 2019 |
| Redhat_linux | — | Upgrade icedtea-webUpgrade icedtea-web-javadocNo solution existsUpgrade icedtea-web-debuginfoUpgrade icedtea-web-devel | Aug 1, 2019 | Jul 31, 2019 |
| Suse | — | Upgrade icedtea-web-javadocUpgrade icedtea-web | Aug 16, 2019 | Jul 31, 2019 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jul 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub