Eclipse / Che
4 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-41034 | The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such… | HIGH | 8.1 | Sep 29, 2021 |
| CVE-2020-14368 | A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't p… | HIGH | 7.1 | Dec 14, 2020 |
| CVE-2020-10689 | che: pods in kubernetes cluster can bypass JWT proxy and send unauthenticated requests to workspace pods | MEDIUM | 6.8 | Apr 3, 2020 |
| CVE-2019-17633 | For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che wo… | HIGH | 8.8 | Dec 19, 2019 |
Showing 1 to 4 of 4 CVEs