Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17633

Опубликовано: 19 дек. 2019
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:eclipse:che:*:*:*:*:*:*:*:*
Версия от 6.16.0 (включая) до 7.3.0 (включая)

EPSS

Процентиль: 67%
0.00536
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.

EPSS

Процентиль: 67%
0.00536
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352
CWE-352