Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg2q-v428-2gph

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

Пакеты

Наименование

org.eclipse.vorto:org.eclipse.vorto.core

maven
Затронутые версииВерсия исправления

< 0.11.0

0.11.0

EPSS

Процентиль: 38%
0.00165
Низкий

8.1 High

CVSS3

Дефекты

CWE-494
CWE-669
CWE-829

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

EPSS

Процентиль: 38%
0.00165
Низкий

8.1 High

CVSS3

Дефекты

CWE-494
CWE-669
CWE-829