PT-2022-11358 · Eclipse · Eclipse P2

Merks

·

Published

2022-07-08

·

Updated

2024-07-12

·

CVE-2021-41037

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse p2 (affected versions not specified)
Description The issue concerns the Eclipse p2 installable units, which can alter the Eclipse Platform installation and the local machine via touchpoints during installation. These touchpoints can modify the command-line used to start the application, injecting settings that require particular attention in terms of security. Although Eclipse p2 has built-in strategies to ensure artifacts are signed, there is no such strategy for the metadata part that configures touchpoints. As a result, it's possible to install a unit that will run malicious code during installation without the user receiving any warning about this installation step being risky when coming from an untrusted source.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2021-41037

Affected Products

Eclipse P2