CVE-2019-17561: High severity oracle netbeans vulnerability
The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-17561?
CVE-2019-17561 is classified as a medium severity vulnerability due to its potential impact on the integrity of the autoupdate process.
How do I fix CVE-2019-17561?
To mitigate CVE-2019-17561, upgrade to Apache NetBeans version 11.3 or later where the autoupdate system's signature validation is improved.
What versions of Apache NetBeans are affected by CVE-2019-17561?
CVE-2019-17561 affects all versions of Apache NetBeans up to and including version 11.2.
Can CVE-2019-17561 affect Oracle GraalVM?
Yes, CVE-2019-17561 can affect Oracle GraalVM Enterprise Edition versions 19.3.2 and 20.1.0 if they leverage the vulnerable NetBeans autoupdate system.
What are the risks associated with CVE-2019-17561?
The main risk associated with CVE-2019-17561 is that an attacker could modify the nbm files, potentially introducing malicious code into the user's environment.