CVE-2021-41033 is a high-severity vulnerability affecting all released versions of Eclipse Equinox up to 4.21. It allows a man-in-the-middle attacker to alter local installations by serving malicious p2 metadata when using unencrypted HTTP p2 repositories. This can lead to the installation of malicious plug-ins capable of executing arbitrary code, resulting in a complete compromise of confidentiality, integrity, and availability. While the attack complexity is high, there is currently no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.21CPE matchmatch criteria | cpe:2.3:a:eclipse:equinox:*:*:*:*:*:*:*:* | ||
4.21CPE matchmatch criteria | cpe:2.3:a:eclipse:equinox:4.21:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.