{"id":"CVE-2018-17191","details":"Apache NetBeans (incubating) 9.0 NetBeans Proxy Auto-Configuration (PAC) interpretation is vulnerable for remote command execution (RCE). Using the nashorn script engine the environment of the javascript execution for the Proxy Auto-Configuration leaks privileged objects, that can be used to circumvent the execution limits. If a different script engine was used, no execution limits were in place. Both vectors allow remote code execution.","modified":"2026-07-08T19:44:23.869002Z","published":"2018-12-31T14:29:00.240Z","references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/d1c37966a316a326ab4ff4d4bc056322e8adcbe984e8145c0ecda7fa%40%3Cdev.netbeans.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106352"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/netbeans","events":[{"introduced":"97904961e496383d6150aef9b78fa8dff8f3e1ce"},{"last_affected":"97904961e496383d6150aef9b78fa8dff8f3e1ce"}],"database_specific":{"extracted_events":[{"introduced":"9.0-NA"},{"last_affected":"9.0-NA"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:apache:netbeans:9.0:-:*:*:*:*:*:*"}}],"versions":["9.0-NA","9.0-vc3","9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-17191.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}