Sicherheitsanfälligkeiten im Auto-Update-Mechanismus von Apache NetBeans
Details about two vulnerabilities in the automated update delivery system for the integrated development environment Apache NetBeans have been revealed, allowing for the substitution of server-sent updates and nbm packages. These issues were resolved discreetly in the release of Apache NetBeans 11.3. The first vulnerability (CVE-2019-17560) is caused by a lack of checking for SSL certificates and host names when loading data via HTTPS, which allows for undetected substitution of downloaded […]
