PT-2019-11657 · Eclipse · Eclipse Vorto

Alexander Edelmann

·

Publicado

2019-04-22

·

Atualizado

2022-05-24

·

CVE-2019-10248

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Eclipse Vorto versions prior to 0.11
Description: The issue allows for a Man-In-The-Middle (MITM) attack, where dependent artifacts could be maliciously compromised because Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. This could result in produced build artifacts of Vorto being infected.
Recommendations: For Eclipse Vorto versions prior to 0.11, update to version 0.11 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10248
GHSA-FG2Q-V428-2GPH

Produtos afetados

Eclipse Vorto