cbcvebase.
CVE-2019-10181
published 2019-07-31

CVE-2019-10181: It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature…

PriorityP341high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.12%
62.6th percentile
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be injected in a JAR file without compromising the signature verification. An attacker could use this flaw to inject code in a trusted JAR. The code would be executed inside the sandbox.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianicedtea-web< icedtea-web 1.8.3-1 (bookworm)icedtea-web 1.8.3-1 (bookworm)
icedtea-web_projecticedtea-web<= 1.7.2
icedtea-web_projecticedtea-web
icedteaicedtea-web
icedteaicedtea-web>= 0 < 1.8.3-11.8.3-1
icedteaicedtea-web>= 0 < 1.8.3-11.8.3-1
icedteaicedtea-web>= 0 < 1.8.3-11.8.3-1
icedteaicedtea-web>= 0 < 1.8.3-11.8.3-1
opensuseleap

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.06.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.