ZeroHour

CVE-2019-17561

CVSS 3.1
7.5 high
EPSS
2%p75
Published
()
Modified
Description

The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

Vendors
apacheoracle
Products
netbeans, graalvm
Weakness
CWE-347
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.