Vulnerabilidades em Eclipse Foundation

170 resultados
Análise Vexday

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2026-8384MEDIUMIn Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admiEPSS 0.3%CVE-2025-55098LOWPotential out-of-bounds read in _ux_host_class_audio_device_type_get()EPSS 0.3%CVE-2026-14336HIGHPIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_kEPSS 0.3%CVE-2023-6194LOWIn Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) rEPSS 0.3%CVE-2026-22551MEDIUMIn Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitraryEPSS 0.3%CVE-2025-55093MEDIUMOut of bound read and write in _nx_ipv4_packet_receive() when handling unicast DHCP messagesEPSS 0.3%CVE-2026-6790MEDIUMIn Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and port) matches what pEPSS 0.3%CVE-2026-4983MEDIUMOpen VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xmlEPSS 0.3%CVE-2026-62927HIGHIn Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculatiEPSS 0.3%CVE-2026-14574MEDIUMIn Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges prefEPSS 0.3%CVE-2026-10051MEDIUMIn Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the EPSS 0.3%CVE-2026-12606MEDIUMEclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, which can be leveragEPSS 0.3%CVE-2026-80515HIGHIn Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whetEPSS 0.3%CVE-2026-19204HIGHA client may send a WebSocket frame with an unknown opcode and a very large declared payload length, causing Jetty to attempt a large memoryEPSS 0.3%CVE-2026-12605CRITICALIn Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-coEPSS 0.3%CVE-2025-11966LOWIn Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted inEPSS 0.3%CVE-2026-84175MEDIUMIn Eclipse Ditto versions 3.0.0 to 3.9.6, the Things service fetches WoT (Web of Things) ThingModels over HTTP from URLs supplied by API useEPSS 0.3%CVE-2024-9408HIGHIn Eclipse GlassFish since version 6.2.5 it is possible to perform a Server Side Request Forgery attack in specific endpoints.EPSS 0.3%CVE-2026-19203HIGHA client may issue specially crafted HTTP/1.1 chunked requests to a Jetty server that cause Jetty and an intermediary proxy to interpret difEPSS 0.3%CVE-2025-12383CRITICALRace Condition allows Bypass of Trust RestrictionsEPSS 0.3%