#VU119113 Missing Authentication for Critical Function in Eclipse Che - CVE-2025-12548

 

#VU119113 Missing Authentication for Critical Function in Eclipse Che - CVE-2025-12548

Published: December 3, 2025


Vulnerability identifier: #VU119113
Vulnerability risk: Critical
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Red
CVE-ID: CVE-2025-12548
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Eclipse Che
Software vendor:
Eclipse

Description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to CHE machine-exec API is exposed by default on port 3333/TCP and does not require authentication. A remote non-authenticated attacker can obtain SSH private keys that are configured by other devspaces user and compromise the affected system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links