{"api_version":"1","generated_at":"2026-07-23T04:35:22+00:00","cve":"CVE-2019-10185","urls":{"html":"https://cve.report/CVE-2019-10185","api":"https://cve.report/api/cve/CVE-2019-10185.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10185","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10185"},"summary":{"title":"CVE-2019-10185","description":"It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-07-31 23:15:00","updated_at":"2023-02-12 23:33:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185","refsource":"CONFIRM","tags":["Issue Tracking","Third Party Advisory"],"title":"1724989 – (CVE-2019-10185) CVE-2019-10185 icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344","name":"https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"fixing CVEs 2019- 10181, 10182, 10185 found by Imre Rad - master by judovana · Pull Request #344 · AdoptOpenJDK/IcedTea-Web · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://seclists.org/bugtraq/2019/Oct/5","name":"20191007 CVE-2019-10181, CVE-2019-10182, CVE-2019-10185: IcedTea-Web vulnerabilities leading to RCE","refsource":"BUGTRAQ","tags":[],"title":"Bugtraq: CVE-2019-10181, CVE-2019-10182, CVE-2019-10185: IcedTea-Web vulnerabilities leading to RCE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html","name":"[debian-lts-announce] 20190909 [SECURITY] [DLA 1914-1] icedtea-web security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 1914-1] icedtea-web security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html","name":"openSUSE-SU-2019:1911","refsource":"SUSE","tags":[],"title":"[security-announce] openSUSE-SU-2019:1911-1: important: Security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327","name":"https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327","refsource":"CONFIRM","tags":["Third Party Advisory"],"title":"upcoming security release 31.7.2019 · Issue #327 · AdoptOpenJDK/IcedTea-Web · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2019-10185","name":"https://access.redhat.com/security/cve/CVE-2019-10185","refsource":"MISC","tags":[],"title":"CVE-2019-10185 - Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1724989","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1724989","refsource":"MISC","tags":[],"title":"1724989 – (CVE-2019-10185) CVE-2019-10185 icedtea-web: directory traversal in the nested jar auto-extraction leading to arbitrary file overwrite","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202107-51","name":"GLSA-202107-51","refsource":"GENTOO","tags":[],"title":"IcedTeaWeb: Multiple vulnerabilities (GLSA 202107-51) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html","name":"http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html","refsource":"MISC","tags":[],"title":"IcedTeaWeb Validation Bypass / Directory Traversal / Code Execution ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2004","name":"https://access.redhat.com/errata/RHSA-2019:2004","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:2003","name":"https://access.redhat.com/errata/RHSA-2019:2003","refsource":"MISC","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10185","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10185","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icedtea-web_project","cpe5":"icedtea-web","cpe6":"1.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"1.7.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icedtea-web_project","cpe5":"icedtea-web","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icetea-web_project","cpe5":"icetea-web","cpe6":"1.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icetea-web_project","cpe5":"icetea-web","cpe6":"1.8.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"1.7.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"icetea-web_project","cpe5":"icetea-web","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"opensuse","cpe5":"leap","cpe6":"15.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10185","qid":"377125","title":"Alibaba Cloud Linux Security Update for icedtea-web (ALINUX3-SA-2022:0037)"},{"cve":"CVE-2019-10185","qid":"710044","title":"Gentoo Linux IcedTeaWeb Multiple Vulnerabilities (GLSA 202107-51)"},{"cve":"CVE-2019-10185","qid":"753209","title":"SUSE Enterprise Linux Security Update for icedtea-web (SUSE-SU-2022:1259-1)"}]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2019-10185","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-22","cweId":"CWE-22"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"IcedTea","product":{"product_data":[{"product_name":"icedtea-web","version":{"version_data":[{"version_affected":"=","version_value":"affects up to and including 1.7.2 and 1.8.2"}]}}]}}]}},"references":{"reference_data":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html","refsource":"MISC","name":"http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00045.html"},{"url":"http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html","refsource":"MISC","name":"http://packetstormsecurity.com/files/154748/IcedTeaWeb-Validation-Bypass-Directory-Traversal-Code-Execution.html"},{"url":"https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327","refsource":"MISC","name":"https://github.com/AdoptOpenJDK/IcedTea-Web/issues/327"},{"url":"https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344","refsource":"MISC","name":"https://github.com/AdoptOpenJDK/IcedTea-Web/pull/344"},{"url":"https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html","refsource":"MISC","name":"https://lists.debian.org/debian-lts-announce/2019/09/msg00008.html"},{"url":"https://seclists.org/bugtraq/2019/Oct/5","refsource":"MISC","name":"https://seclists.org/bugtraq/2019/Oct/5"},{"url":"https://security.gentoo.org/glsa/202107-51","refsource":"MISC","name":"https://security.gentoo.org/glsa/202107-51"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185","refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10185"}]},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":8.2,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L","version":"3.0"}]}},"nvd":{"publishedDate":"2019-07-31 23:15:00","lastModifiedDate":"2023-02-12 23:33:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.4},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:icedtea-web_project:icedtea-web:*:*:*:*:*:*:*:*","versionEndIncluding":"1.7.2","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:icedtea-web_project:icedtea-web:1.8.2:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10185","Ordinal":"148402","Title":"CVE-2019-10185","CVE":"CVE-2019-10185","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10185","Ordinal":"1","NoteData":"It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and, possibly, break out of the sandbox.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10185","Ordinal":"2","NoteData":"2019-07-31","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10185","Ordinal":"3","NoteData":"2021-07-24","Type":"Other","Title":"Modified"}]}}}