CVE-2020-10689
CVE-2020-10689 is a medium-severity vulnerability in Eclipse Che with a CVSS 3.x base score of 6.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-862.
Key facts
- Severity: Medium (CVSS 3.x base score 6.4)
- CVSS v2: 4.9
- EPSS exploit prediction: 1% (54th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-862
- Affected product: Eclipse Che
- Published:
- Last modified:
Description
A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
Frequently asked questions
- What is CVE-2020-10689?
- A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.
- How severe is CVE-2020-10689?
- CVE-2020-10689 has a CVSS 3.x base score of 6.4, rated medium severity. It is exploitable over an adjacent network with high attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2020-10689 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (54th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-10689?
- CVE-2020-10689 affects Eclipse Che. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-10689?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-10689 published?
- CVE-2020-10689 was published on 2020-04-03 and last updated on 2026-06-17.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10689
- https://github.com/eclipse/che/issues/15651
Affected products (1)
- cpe:2.3:a:eclipse:che:*:*:*:*:*:*:*:*
More vulnerabilities in Eclipse Che
- CVE-2019-17633 — High (CVSS 8.8): For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could…
- CVE-2021-41034 — High (CVSS 8.1): The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP…
- CVE-2020-14368 — High (CVSS 7.1): A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with…
All CVEs affecting Eclipse Che →
Other CWE-862 (Missing Authorization) vulnerabilities
- CVE-2026-101000 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file…
- CVE-2026-97360 — Critical (CVSS 10.0): HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows…
- CVE-2026-65381 — Critical (CVSS 10.0): A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the…
- CVE-2026-81648 — Critical (CVSS 10.0): The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX…
- CVE-2026-77770 — Critical (CVSS 10.0): The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a…
- CVE-2026-65667 — Critical (CVSS 10.0): Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Browse all CWE-862 (Missing Authorization) vulnerabilities →