CVE-2019-17633

HIGH

Eclipse Che 6.16.0-7.3.0 - Unauthenticated Workspace Creation via CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-17633. PoCs published by mgrube.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2019-17633, a CSRF vulnerability in Eclipse Che leading to RCE. It explains the root cause (CORS misconfiguration) and includes a high-level exploitation method, but lacks functional exploit code.

Description

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitrary Che workspace. Che with no authentication and no TLS is not usually deployed on a public network but is often used for local installations (e.g. on personal laptops). In that case, even if the Che API is not exposed externally, some javascript running in the local browser is able to send requests to it.

Exploits (1)

nomisec WRITEUP 10 stars
by mgrube · poc
https://github.com/mgrube/CVE-2019-17633

This repository provides a detailed technical analysis of CVE-2019-17633, a CSRF vulnerability in Eclipse Che leading to RCE. It explains the root cause (CORS misconfiguration) and includes a high-level exploitation method, but lacks functional exploit code.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Eclipse Che before versions 7.3.0 and 7.4.1
No auth needed
Prerequisites: Target must be running Eclipse Che in standalone mode · Target must visit an attacker-controlled HTTP page
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugs.eclipse.org/bugs/show_bug.cgi?id=551596

Scores

CVSS v3 8.8
EPSS 0.0054
EPSS Percentile 67.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
eclipse/che 6.16.0 - 7.3.0
Published Dec 19, 2019
Tracked Since Feb 18, 2026