PT-2020-12967 · Apache · Apache Netbeans

Published

2020-09-09

·

Updated

2021-03-26

·

CVE-2020-11986

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache NetBeans versions up to and including 12.0
Description The issue arises from the execution of build scripts to analyze gradle projects, which Apache NetBeans follows. This pattern causes the build script code to be invoked at project load time. Without requesting user consent for project analysis at load time, potentially malicious code from an external source can be executed.
Recommendations For Apache NetBeans versions up to and including 12.0, consider disabling the automatic execution of build scripts at project load time until a patch is available. Restrict access to external project sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-11986

Affected Products

Apache Netbeans