CVE-2019-17633 Information
Feb 14, 2021
cve
Description
For Eclipse Che versions 6.16 to 7.3.0 with both authentication and TLS disabled visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case even if the Che API is not exposed externally some javascript running in the local browser is able to send requests to it.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://bugs.eclipse.org/bugs/show_bug.cgi?id=551596
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: