漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che.
CVSS Information
N/A
Vulnerability Type
通信信道中传输过程中消息完整性的不正确执行
Vulnerability Title
Eclipse Che 安全漏洞
Vulnerability Description
Eclipse Che是Eclipse基金会的一套基于Java的开源在线集成开发环境(IDE)。 Eclipse Che 存在安全漏洞,该漏洞源于Eclipse Che版本6的语言栈构建存在安全问题。成功利用漏洞的攻击者可用任意的二进制文件替换程序原来的二进制文件。
CVSS Information
N/A
Vulnerability Type
N/A