PT-2020-4106 · Apache · Apache Netbeans
Filip Ceglik
·
Published
2020-03-30
·
Updated
2023-01-27
·
CVE-2019-17560
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions:
Apache NetBeans versions up to and including 11.2
Description:
The issue is related to the Apache NetBeans autoupdate system, which does not validate SSL certificates and hostnames for https-based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. The vulnerability may impact the confidentiality and integrity of protected information.
Recommendations:
For Apache NetBeans versions up to and including 11.2, consider disabling the autoupdate feature until a patch is available to prevent potential exploitation. Restrict access to the autoupdate system to minimize the risk of malicious code injection. Avoid using the autoupdate system for https-based downloads until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Netbeans