RELEASE240
5 years ago
1 months ago
Known vulnerabilities in the org.netbeans.api:org-netbeans-modules-autoupdate-services package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Improper Certificate Validation such that the autoupdate system does not validate SSL certificates and hostnames for HTTPS based downloads. This allows an attacker to intercept downloads of autoupdates and modify the download, potentially injecting malicious code. How to fix Improper Certificate Validation? Upgrade | [,RELEASE113) |
Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature such that the autoupdate system does not fully validate code signatures. An attacker could modify the downloaded How to fix Improper Verification of Cryptographic Signature? Upgrade | [,RELEASE113) |