cbcvebase.
CVE-2019-17561
published 2020-03-30

CVE-2019-17561: The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code…

PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.63%
73.6th percentile
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachenetbeans<= 11.2
apachenetbeans>= 0 < 12.1-112.1-1
apachenetbeans>= 0 < 12.1-112.1-1
apachenetbeans>= 0 < 12.1-112.1-1
apachenetbeans>= 0 < 12.1-112.1-1
debiannetbeans< netbeans 12.1-1 (bookworm)netbeans 12.1-1 (bookworm)
oraclegraalvm
oraclegraalvm

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.