Vulnerability in Apache NetBeans Autoupdate System Allows Code Injection
CVE-2019-17560

9.1CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
30 March 2020

Summary

The autoupdate system of Apache NetBeans is susceptible to a vulnerability stemming from its failure to properly validate SSL certificates and hostnames when downloading updates over HTTPS. This oversight permits an attacker to potentially intercept and modify the downloads, enabling the injection of malicious code into the software. As such, users of Apache NetBeans versions up to and including 11.2 are at risk if they rely on this feature without additional protective measures.

Affected Version(s)

Apache NetBeans through 11.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.