Vulnerability Description
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Platform | <= 4.18 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855ExploitIssue TrackingPatch
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=569855ExploitIssue TrackingPatch
FAQ
What is CVE-2020-27225?
CVE-2020-27225 is a vulnerability with a CVSS score of 7.8 (HIGH). In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue ac...
How severe is CVE-2020-27225?
CVE-2020-27225 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27225?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Platform.