CVE-2019-17633

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-17633
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-17633.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-17633
Published
2019-12-19T17:15:12Z
Modified
2024-11-21T04:32:40Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.

References

Affected packages

Git / github.com/eclipse/che

Affected ranges

Type
GIT
Repo
https://github.com/eclipse/che
Events