Vulnerabilities nyob rau hauv Apache NetBeans auto-update mechanism

Cov ntaub ntawv nthuav tawm hais txog ob qhov tsis zoo hauv qhov system ntawm kev xa tawm tsis siv neeg hloov tshiab rau Apache NetBeans kev sib koom ua ke ib puag ncig kev txhim kho, uas ua rau nws muaj peev xwm ua tsis tau hloov tshiab thiab nbm pob xa los ntawm lub server. Cov teeb meem tau ntsiag to kho hauv kev tso tawm Apache NetBeans 11.3.

Thawj qhov yooj yim (CVE-2019-17560) yog tshwm sim los ntawm qhov tsis muaj pov thawj ntawm SSL daim ntawv pov thawj thiab hostnames thaum rub tawm cov ntaub ntawv hla HTTPS, uas ua rau nws muaj peev xwm surreptitiously spoof cov ntaub ntawv rub tawm. Qhov thib ob vulnerability (CVE-2019-17561) yog txuam nrog kev tshawb xyuas tsis tiav ntawm qhov hloov tshiab rub tawm siv tus lej kos npe, uas tso cai rau tus neeg tawm tsam ntxiv cov lej ntxiv rau nbm cov ntaub ntawv yam tsis muaj kev cuam tshuam rau kev ncaj ncees ntawm pob.

Tau qhov twg los: opennet.ru

Ntxiv ib saib