PT-2022-11358 · Eclipse · Eclipse P2
Merks
·
Published
2022-07-08
·
Updated
2024-07-12
·
CVE-2021-41037
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse p2 (affected versions not specified)
Description
The issue concerns the Eclipse p2 installable units, which can alter the Eclipse Platform installation and the local machine via touchpoints during installation. These touchpoints can modify the command-line used to start the application, injecting settings that require particular attention in terms of security. Although Eclipse p2 has built-in strategies to ensure artifacts are signed, there is no such strategy for the metadata part that configures touchpoints. As a result, it's possible to install a unit that will run malicious code during installation without the user receiving any warning about this installation step being risky when coming from an untrusted source.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse P2