Back

CRITICAL

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads

Published Mar 30, 2020

Description

The "Apache NetBeans" autoupdate system does not validate SSL certificates and hostnames for https based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. “Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Mar 30, 2020
Updated Aug 5, 2024
Reserved Oct 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Mar 30, 2020
Updated Aug 5, 2024
Exploited since n/a
EUVD-2022-2969 GHSA-7C2M-VWXW-5QWW