Vulnerability in Apache NetBeans Autoupdate System Allows Code Injection
CVE-2019-17560
9.1CRITICAL
What is CVE-2019-17560?
The autoupdate system of Apache NetBeans is susceptible to a vulnerability stemming from its failure to properly validate SSL certificates and hostnames when downloading updates over HTTPS. This oversight permits an attacker to potentially intercept and modify the downloads, enabling the injection of malicious code into the software. As such, users of Apache NetBeans versions up to and including 11.2 are at risk if they rely on this feature without additional protective measures.
Affected Version(s)
Apache NetBeans through 11.2