PT-2019-12489 · Eclipse · Eclipse Buildship
Published
2019-06-14
·
Updated
2023-03-24
·
CVE-2019-11770
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Buildship versions prior to 3.1.1
Description
The issue arises from Eclipse Buildship resolving dependencies over HTTP instead of HTTPS, making the artifacts susceptible to Man-In-The-Middle (MITM) attacks. This could lead to the malicious compromise of these artifacts and the infection of build artifacts. Furthermore, if any dependencies such as JARs were compromised, developers using them could remain infected even after updating to fix this issue.
Recommendations
For Eclipse Buildship versions prior to 3.1.1, update to version 3.1.1 or later to resolve the issue. As a temporary workaround, consider configuring the build files to resolve dependencies over HTTPS instead of HTTP to minimize the risk of exploitation. Restrict access to dependencies resolved over HTTP to minimize the risk of infection.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Buildship