MEDIUM🇵🇱 Wersja polska

CVE-2020-10689

CVSS 6.4v3.1pub. 2020-04-03upd. 2024-11-21

A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Eclipse Che

    APP
    Eclipse
    < 7.9.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-41034HIGH8.1same product

The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HT...

CVE-2020-14368HIGH7.1same product

A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured...

CVE-2019-17633HIGH8.8same product

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web si...

CVE-2026-12605CRITICAL9.6PL ✓same vendor

Eclipse GlassFish: CSRF+SSRF w DownloadServlet umożliwia przejęcie domeny

CVE-2026-60007CRITICAL9.1PL ✓same vendor

Eclipse Milo: padding oracle w uwierzytelnianiu OPC-UA umożliwia odzyskanie hasła