Improper Input Validation in net.sf.robocode:robocode.host allows for external service interaction
Critical severity
GitHub Reviewed
Published
Apr 2, 2019
to the GitHub Advisory Database
•
Updated Sep 25, 2023
Description
Published by the National Vulnerability Database
Mar 30, 2019
Published to the GitHub Advisory Database
Apr 2, 2019
Reviewed
Jun 16, 2020
Last updated
Sep 25, 2023
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.
References