← Back

CVE-2019-17560

nvd nist
Published: Mar 30, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

Affected (3)

Products: Apache: Netbeans · Oracle: Graalvm
1 product
Netbeans
1 product
Graalvm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 11.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 19.3.2
Version 20.1.0

References (4)

Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.