Описание
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
It was found that the Eclipse Platform does not authenticate requests to the Help subsystem on the local web server. A local attacker could use this vulnerability to disrupt the Eclipse user's session, potentially causing Eclipse to damage or disclose data owned by that user.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | eclipse | Out of support scope | ||
| Red Hat Enterprise Linux 8 | eclipse | Will not fix | ||
| Red Hat Developer Tools | rh-eclipse | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-apache-sshd | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-batik | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-eclipse | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-eclipse-egit | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-eclipse-emf | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-eclipse-jgit | Fixed | RHEA-2021:1441 | 28.04.2021 |
| Red Hat Developer Tools | rh-eclipse-jakarta-annotations | Fixed | RHEA-2021:1441 | 28.04.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsyst ...
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
EPSS
7.8 High
CVSS3