CVE-2019-17561
published 2020-03-30CVE-2019-17561: The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.63%
73.6th percentile
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | netbeans | <= 11.2 | — |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| apache | netbeans | >= 0 < 12.1-1 | 12.1-1 |
| debian | netbeans | < netbeans 12.1-1 (bookworm) | netbeans 12.1-1 (bookworm) |
| oracle | graalvm | — | — |
| oracle | graalvm | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Verification of Cryptographic Signature in Apache Netbeans
osv·2022-05-24
CVE-2019-17561 [HIGH] Improper Verification of Cryptographic Signature in Apache Netbeans
Improper Verification of Cryptographic Signature in Apache Netbeans
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. NetBeans releases before the Apache transition started may also be affected.
GHSA
Improper Verification of Cryptographic Signature in Apache Netbeans
ghsa·2022-05-24
CVE-2019-17561 [HIGH] CWE-20 Improper Verification of Cryptographic Signature in Apache Netbeans
Improper Verification of Cryptographic Signature in Apache Netbeans
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. NetBeans releases before the Apache transition started may also be affected.
OSV
CVE-2019-17561: The "Apache NetBeans" autoupdate system does not fully validate code signatures
osv·2020-03-30·CVSS 7.5
CVE-2019-17561 [HIGH] CVE-2019-17561: The "Apache NetBeans" autoupdate system does not fully validate code signatures
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Debian
CVE-2019-17561: netbeans - The "Apache NetBeans" autoupdate system does not fully validate code signatures....
vendor_debian·2019·CVSS 7.5
CVE-2019-17561 [HIGH] CVE-2019-17561: netbeans - The "Apache NetBeans" autoupdate system does not fully validate code signatures....
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Scope: local
bookworm: resolved (fixed in 12.1-1)
bullseye: resolved (fixed in 12.1-1)
forky: resolved (fixed in 12.1-1)
sid: resolved (fixed in 12.1-1)
trixie: resolved (fixed in 12.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.apache.org/thread.html/rb218aa720fc525f63d91761fbf67854f454ce7a697dbbee2001ae8b1%40%3Cdev.netbeans.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://lists.apache.org/thread.html/rb218aa720fc525f63d91761fbf67854f454ce7a697dbbee2001ae8b1%40%3Cdev.netbeans.apache.org%3Ehttps://www.oracle.com/security-alerts/cpujul2020.html
2020-03-30
Published