CVE-2019-10240
Summary
| CVE | CVE-2019-10240 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-03 18:29:00 UTC |
| Updated | 2021-10-28 13:54:00 UTC |
| Description | Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected. |
Risk And Classification
Problem Types: CWE-319
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 546053 – (CVE-2019-10240) Eclipse hawkBit: New CVE Request | CONFIRM | bugs.eclipse.org | Exploit, Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983480 Java (maven) Security Update for org.eclipse.hawkbit:hawkbit-boot-starter-ddi-api (GHSA-jwqm-c9f2-2cq3)