Vulnerabilities in the auto-update mechanism of Apache NetBeans

Revealed information about two vulnerabilities in the automatic update delivery system for the integrated development environment Apache NetBeans, which allow the server's updates and nbm packages to be replaced. The issues were resolved discreetly in the release Apache NetBeans 11.3.

The first vulnerability (CVE-2019-17560) is caused by the lack of SSL certificate and hostname verification when loading data via HTTPS, allowing the downloaded data to be replaced unnoticed. The second vulnerability (CVE-2019-17561) is related to inadequate verification of the downloaded update by digital signature, enabling an attacker to inject additional code into nbm files without compromising the integrity of the package.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster