Количество 2
Количество 2
CVE-2019-1010260
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.
GHSA-r8h9-hq9c-2p5c
High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-1010260 Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261. | CVSS3: 8.1 | 0% Низкий | почти 7 лет назад | |
GHSA-r8h9-hq9c-2p5c High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-core | CVSS3: 8.1 | 0% Низкий | почти 7 лет назад |
Уязвимостей на страницу