GHSA-7c2m-vwxw-5qww
Dashboard / Vulnerabilities / GHSA-7c2m-vwxw-5qww
Summary: Improper Certificate Validation in Apache Netbeans
Details: The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. NetBeans releases before the Apache transition started may also be affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-17560, https://lists.apache.org/thread.html/r354d7654efa1050539fe56a3257696d1faeea4f3f9b633c29ec89609%40%3Cdev.netbeans.apache.org%3E, https://www.oracle.com/security-alerts/cpujul2020.html
Affected packages
Package
Name: org.codehaus.mevenide:netbeans
Purl: pkg:maven/org.codehaus.mevenide/netbeans
Affected ranges
Type: ECOSYSTEM
Events:
