Description
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-28186 | In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code. |
References
| Link | Providers |
|---|---|
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=575688 |
|
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-04T02:59:30.351Z
Reserved: 2021-09-13T00:00:00.000Z
Link: CVE-2021-41033
No data.
Status : Modified
Published: 2021-09-13T21:15:07.937
Modified: 2024-11-21T06:25:19.170
Link: CVE-2021-41033
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD