First published: Mon Mar 30 2020(Updated: )
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache NetBeans | <=11.2 | |
Oracle GraalVM Enterprise Edition | =19.3.2 | |
Oracle GraalVM Enterprise Edition | =20.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17561 is classified as a medium severity vulnerability due to its potential impact on the integrity of the autoupdate process.
To mitigate CVE-2019-17561, upgrade to Apache NetBeans version 11.3 or later where the autoupdate system's signature validation is improved.
CVE-2019-17561 affects all versions of Apache NetBeans up to and including version 11.2.
Yes, CVE-2019-17561 can affect Oracle GraalVM Enterprise Edition versions 19.3.2 and 20.1.0 if they leverage the vulnerable NetBeans autoupdate system.
The main risk associated with CVE-2019-17561 is that an attacker could modify the nbm files, potentially introducing malicious code into the user's environment.