Описание
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
Ссылки
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
- ExploitPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.9.0 (исключая)
cpe:2.3:a:arrow-kt:arrow:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00319
Низкий
8.1 High
CVSS3
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-311
Связанные уязвимости
CVSS3: 5.9
github
почти 7 лет назад
Missing Encryption of Sensitive Data in arrow-kt Arrow
EPSS
Процентиль: 55%
0.00319
Низкий
8.1 High
CVSS3
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-311