The Eclipse Foundation Vulnerabilities and Affected Products
Vulnerabilities associated with Eclipse Equinox p2.
Products
Clear product- Eclipse Jetty23 vulnerabilities
- Eclipse Mosquitto16 vulnerabilities
- Eclipse OpenJ914 vulnerabilities
- Eclipse Theia6 vulnerabilities
- Eclipse Vert.x6 vulnerabilities
- Eclipse Californium3 vulnerabilities
- Eclipse Kura3 vulnerabilities
- Eclipse OMR3 vulnerabilities
- Eclipse BIRT2 vulnerabilities
- Eclipse Che2 vulnerabilities
- Eclipse Hawkbit2 vulnerabilities
- Eclipse Hono2 vulnerabilities
- Eclipse Memory Analyzer2 vulnerabilities
- @theia/plugin-ext1 vulnerability
- Eclipse BIRT (Business Intelligence Reporting Tool)1 vulnerability
- Eclipse Buildship1 vulnerability
- Eclipse Equinox1 vulnerability
- Eclipse Equinox p21 vulnerability
- Eclipse GlassFish1 vulnerability
- Eclipse Jersey1 vulnerability
- Eclipse Lyo1 vulnerability
- Eclipse Paho1 vulnerability
- Eclipse Paho MQTT C Client1 vulnerability
- Eclipse Platform1 vulnerability
- Eclipse Sphinx1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-41037CRITICAL | In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings that usually require particular attention in term of security. Although p2 has built-in strategies to ensure artifacts are signed and then to help establish trust, there is no such strategy for the metadata part that doe… CWE-829Jul 8, 2022 | CVSS10.0v3.1 | EPSS0.806% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |