The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published: 2021-09-29T21:35:09

Updated: 2024-08-04T02:59:31.177Z

Reserved: 2021-09-13T00:00:00

Link: CVE-2021-41034

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-29T22:15:07.367

Modified: 2021-10-07T20:35:06.457

Link: CVE-2021-41034

cve-icon Redhat

No data.