It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.
CVSS Details
- CVSS 3.1 Base Score: 8.2
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | no-centos-package-available | Aug 28, 2019 | Jul 31, 2019 |
| Debian | debian-upgrade-icedtea-web | Sep 11, 2019 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-icedtea-web | Sep 12, 2019 | Jul 31, 2019 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-icedtea-web | Aug 31, 2020 | Jul 31, 2019 | |
| Oracle_linux | — | oracle-linux-upgrade-icedtea-weboracle-linux-upgrade-icedtea-web-develoracle-linux-upgrade-icedtea-web-javadoc | Jul 21, 2020 | Jul 31, 2019 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-icedtea-webredhat-upgrade-icedtea-web-debuginforedhat-upgrade-icedtea-web-develredhat-upgrade-icedtea-web-javadoc | Aug 1, 2019 | Jul 31, 2019 | |
| Suse | — | suse-upgrade-icedtea-websuse-upgrade-icedtea-web-javadoc | Aug 16, 2019 | Jul 31, 2019 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Jul 31, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub