PT-2019-12489 · Eclipse · Eclipse Buildship

Published

2019-06-14

·

Updated

2023-03-24

·

CVE-2019-11770

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Eclipse Buildship versions prior to 3.1.1
Description The issue arises from Eclipse Buildship resolving dependencies over HTTP instead of HTTPS, making the artifacts susceptible to Man-In-The-Middle (MITM) attacks. This could lead to the malicious compromise of these artifacts and the infection of build artifacts. Furthermore, if any dependencies such as JARs were compromised, developers using them could remain infected even after updating to fix this issue.
Recommendations For Eclipse Buildship versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider configuring the build files to resolve dependencies over HTTPS instead of HTTP to minimize the risk of exploitation. Restrict access to dependencies resolved over HTTP to minimize the risk of infection.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-11770

Affected Products

Eclipse Buildship