CVE-2021-41034
Estado: ModificadaAlta (8.1)—
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-924
- CWE-924
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-41034",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "emo@eclipse.org",
"affectedData": [
{
"vendor": "The Eclipse Foundation",
"product": "Eclipse Che",
"versions": [
{
"status": "affected",
"version": "6.0",
"lessThan": "unspecified",
"versionType": "custom"
},
{
"status": "affected",
"version": "unspecified",
"lessThan": "7.0",
"versionType": "custom"
}
]
}
]
}
],
"published": "2021-09-29T22:15:07.367",
"references": [
{
"url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=540989",
"tags": [
"Vendor Advisory"
],
"source": "emo@eclipse.org"
},
{
"url": "https://bugs.eclipse.org/bugs/show_bug.cgi?id=540989",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "emo@eclipse.org",
"description": [
{
"lang": "en",
"value": "CWE-924"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-924"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with arbitrary ones. The stacks involved are Java 8 (alpine and centos), Android and PHP. The vulnerability is not exploitable at runtime but only when building Che."
},
{
"lang": "es",
"value": "La compilación de algunas pilas de lenguaje de Eclipse Che versión 6, incluye una extracción de algunos binarios desde un endpoint HTTP no seguro. Como consecuencia, las compilaciones de dichos stacks son vulnerables a ataques de tipo MITM que permiten la sustitución de los binarios originales por otros arbitrarios. Las pilas implicadas son Java 8 (alpine y centos), Android y PHP. La vulnerabilidad no es explotable en tiempo de ejecución sino sólo cuando se construye el Che"
}
],
"lastModified": "2026-06-17T04:07:46.963",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:eclipse:che:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27CF1583-CC8A-408D-977D-5039879B886C",
"versionEndExcluding": "7.0.0",
"versionStartIncluding": "6.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "emo@eclipse.org"
}