Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64f4-p4m8-4j89

Опубликовано: 13 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9

Описание

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

EPSS

Процентиль: 51%
0.0028
Низкий

9 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9
nvd
26 дней назад

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated JSON-RPC / websocket API exposed on TCP port 3333.

EPSS

Процентиль: 51%
0.0028
Низкий

9 Critical

CVSS3

Дефекты

CWE-306