CVE-2024-0740: Eclipse Target Management <= 4.5.500 Command Injection
Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication.
The fixed version is included in Eclipse IDE 2024-03
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0740?
CVE-2024-0740 has a high severity level due to its remote code execution capabilities without requiring authentication.
How do I fix CVE-2024-0740?
To fix CVE-2024-0740, upgrade to Eclipse Target Management: Terminal and Remote System Explorer (RSE) version 2024-03 or later.
What software is affected by CVE-2024-0740?
CVE-2024-0740 affects Eclipse Target Management: Terminal and Remote System Explorer (RSE) versions up to and including 4.5.400.
Does CVE-2024-0740 require user authentication to exploit?
No, CVE-2024-0740 does not require user authentication, making it particularly vulnerable.
What are the potential impacts of CVE-2024-0740?
The potential impacts of CVE-2024-0740 include unauthorized remote code execution on affected systems.