about two vulnerabilities in the automatic update delivery system for the integrated development environment Apache NetBeans, which allow the server's updates and nbm packages to be replaced. The issues were resolved discreetly in the release .
(CVE-2019-17560) is caused by the lack of SSL certificate and hostname verification when loading data via HTTPS, allowing the downloaded data to be replaced unnoticed. (CVE-2019-17561) is related to inadequate verification of the downloaded update by digital signature, enabling an attacker to inject additional code into nbm files without compromising the integrity of the package.
Source: opennet.ru
