PT-2019-12489 · Eclipse · Eclipse Buildship
CVE-2019-11770
·
Publicado
2019-06-14
·
Atualizado
2023-03-24
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Buildship versions prior to 3.1.1
Description
The issue arises from Eclipse Buildship resolving dependencies over HTTP instead of HTTPS, making the artifacts susceptible to Man-In-The-Middle (MITM) attacks. This could lead to the malicious compromise of these artifacts and the infection of build artifacts. Furthermore, if any dependencies such as JARs were compromised, developers using them could remain infected even after updating to fix this issue.
Recommendations
For Eclipse Buildship versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider configuring the build files to resolve dependencies over HTTPS instead of HTTP to minimize the risk of exploitation. Restrict access to dependencies resolved over HTTP to minimize the risk of infection.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Eclipse Buildship