A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10689 | Issue Tracking Patch Third Party Advisory |
https://github.com/eclipse/che/issues/15651 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2020-04-03 15:15
Updated : 2024-02-28 17:47
NVD link : CVE-2020-10689
Mitre link : CVE-2020-10689
CVE.ORG link : CVE-2020-10689
JSON object : View
Products Affected
eclipse
- che
CWE