Description
A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
Published: 2020-04-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-3123 A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
History

No history.

Subscriptions

Eclipse Che
Redhat Codeready Workspaces
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T11:06:11.157Z

Reserved: 2020-03-20T00:00:00.000Z

Link: CVE-2020-10689

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-03T15:15:14.420

Modified: 2024-11-21T04:55:51.600

Link: CVE-2020-10689

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-24T00:00:00Z

Links: CVE-2020-10689 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses