#VU119113 Missing Authentication for Critical Function in Eclipse Che - CVE-2025-12548
Published: December 3, 2025
Eclipse Che
Eclipse
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to CHE machine-exec API is exposed by default on port 3333/TCP and does not require authentication. A remote non-authenticated attacker can obtain SSH private keys that are configured by other devspaces user and compromise the affected system.