Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r8h9-hq9c-2p5c

Опубликовано: 08 апр. 2019
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-core

Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.

Пакеты

Наименование

com.github.shyiko.ktlint:ktlint-core

maven
Затронутые версииВерсия исправления

< 0.30.0

0.30.0

EPSS

Процентиль: 44%
0.00216
Низкий

8.1 High

CVSS3

Дефекты

CWE-319

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.

EPSS

Процентиль: 44%
0.00216
Низкий

8.1 High

CVSS3

Дефекты

CWE-319