CVE-2019-17560
published 2020-03-30CVE-2019-17560: The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept…
PriorityP350critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
2.01%
78.7th percentile
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | netbeans | <= 11.2 | — |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| debian | netbeans | < netbeans 12.1-1 (bookworm) | netbeans 12.1-1 (bookworm) |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1LOW
vendor_oracle9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Certificate Validation in Apache Netbeans
osv·2022-05-24
CVE-2019-17560 [CRITICAL] Improper Certificate Validation in Apache Netbeans
Improper Certificate Validation in Apache Netbeans
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. NetBeans releases before the Apache transition started may also be affected.
GHSA
Improper Certificate Validation in Apache Netbeans
ghsa·2022-05-24
CVE-2019-17560 [CRITICAL] CWE-295 Improper Certificate Validation in Apache Netbeans
Improper Certificate Validation in Apache Netbeans
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. NetBeans releases before the Apache transition started may also be affected.
OSV
CVE-2019-17560: The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads
osv·2020-03-30·CVSS 9.1
CVE-2019-17560 [CRITICAL] CVE-2019-17560: The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Oracle
Oracle Oracle GraalVM Risk Matrix: GraalVM Compiler (Apache NetBeans) — CVE-2019-17560
vendor_oracle·2020-07-15·CVSS 9.1
CVE-2019-17560 [CRITICAL] Oracle Oracle GraalVM Risk Matrix: GraalVM Compiler (Apache NetBeans) — CVE-2019-17560
Oracle Oracle GraalVM Risk Matrix: GraalVM Compiler (Apache NetBeans) vulnerability
CVE: CVE-2019-17560
CVSS: 9.1
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Debian
CVE-2019-17560: netbeans - The "Apache NetBeans" autoupdate system does not validate SSL certificates and h...
vendor_debian·2019·CVSS 9.1
CVE-2019-17560 [CRITICAL] CVE-2019-17560: netbeans - The "Apache NetBeans" autoupdate system does not validate SSL certificates and h...
The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Scope: local
bookworm: resolved (fixed in 12.1-1)
bullseye: resolved (fixed in 12.1-1)
forky: resolved (fixed in 12.1-1)
sid: resolved (fixed in 12.1-1)
trixie: resolved (fixed in 12.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/r354d7654efa1050539fe56a3257696d1faeea4f3f9b633c29ec89609%40%3Cdev.netbeans.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://lists.apache.org/thread.html/r354d7654efa1050539fe56a3257696d1faeea4f3f9b633c29ec89609%40%3Cdev.netbeans.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2020.html
2020-03-30
Published