CVE-2021-41033: Channel Accessible by Non-Endpoint
(updated )
Eclipse Equinox installations can be vulnerable to man-in-the-middle attacks if using p2
repos that are HTTP; that can then be exploited to serve incorrect p2
metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code.
References
Detect and mitigate CVE-2021-41033 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →