A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2020-04-03T14:29:59

Updated: 2024-08-04T11:06:11.157Z

Reserved: 2020-03-20T00:00:00

Link: CVE-2020-10689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-03T15:15:14.420

Modified: 2024-11-21T04:55:51.600

Link: CVE-2020-10689

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-24T00:00:00Z

Links: CVE-2020-10689 - Bugzilla