Code Injection Vulnerability in Apache NetBeans Autoupdate System
CVE-2019-17561
7.5HIGH
Summary
The autoupdate system in Apache NetBeans does not adequately validate code signatures, allowing an attacker to potentially modify downloaded nbm files. This vulnerability could lead to the inclusion of malicious code when users update their software, particularly impacting versions of Apache NetBeans through 11.2. Users are encouraged to ensure that their installations are updated and to apply any patches or mitigations offered by the vendor.
Affected Version(s)
Apache NetBeans through 11.2
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved