Description
Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0427 | Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled DNS zone, because of a .openStream call within java.net.URL. |
Github GHSA |
GHSA-q2xp-75m7-gv52 | Improper Input Validation in net.sf.robocode:robocode.host allows for external service interaction |
References
History
Mon, 22 Dec 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Robocode
Robocode robocode |
|
| CPEs | cpe:2.3:a:robocode_project:robocode:-:*:*:*:*:*:*:* |
cpe:2.3:a:robocode:robocode:*:*:*:*:*:*:*:* cpe:2.3:a:robocode:robocode:-:*:*:*:*:*:*:* |
| Vendors & Products |
Robocode Project
Robocode Project robocode |
Robocode
Robocode robocode |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:31:59.962Z
Reserved: 2019-03-30T00:00:00.000Z
Link: CVE-2019-10648
No data.
Status : Modified
Published: 2019-03-30T13:29:00.657
Modified: 2025-12-22T17:41:41.827
Link: CVE-2019-10648
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA