Show plain JSON{"affected_release": [{"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-1:4.19-4.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-apache-sshd-1:2.6.0-1.2.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-batik-0:1.14-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-eclipse-1:4.19-1.3.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-eclipse-egit-0:5.11.0-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-eclipse-emf-1:2.25.0-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-eclipse-jgit-0:5.11.0-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-jakarta-annotations-0:1.3.5-7.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-jetty-0:9.4.38-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-jgit-0:5.11.0-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-objectweb-asm-0:9.1-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-takari-polyglot-0:0.4.6-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-tycho-0:2.2.0-4.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}, {"advisory": "RHEA-2021:1441", "cpe": "cpe:/a:redhat:devtools:2021", "package": "rh-eclipse-xmlgraphics-commons-0:2.6-1.1.el7_9", "product_name": "Red Hat Developer Tools", "release_date": "2021-04-28T00:00:00Z"}], "bugzilla": {"description": "eclipse: Help Subsystem does not authenticate active help requests", "id": "1939630", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1939630"}, "csaw": false, "cvss3": {"cvss3_base_score": "7.8", "cvss3_scoring_vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "status": "verified"}, "cwe": "CWE-287", "details": ["In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.", "It was found that the Eclipse Platform does not authenticate requests to the Help subsystem on the local web server. A local attacker could use this vulnerability to disrupt the Eclipse user's session, potentially causing Eclipse to damage or disclose data owned by that user."], "name": "CVE-2020-27225", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "eclipse", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Will not fix", "package_name": "eclipse", "product_name": "Red Hat Enterprise Linux 8"}], "public_date": "2021-03-09T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2020-27225\nhttps://nvd.nist.gov/vuln/detail/CVE-2020-27225"], "threat_severity": "Moderate"}