← Back

CVE-2019-17561

nvd nist
Published: Mar 30, 2020Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

Affected (3)

Products: Apache: Netbeans · Oracle: Graalvm
1 product
Netbeans
1 product
Graalvm
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 11.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 19.3.2
Version 20.1.0

References (4)

Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.