CVE-2019-11404
Summary
| CVE | CVE-2019-11404 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-22 11:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Releases are built/executed/released in the context of insecure/untrusted code · Issue #35 · arrow-kt/ank · GitHub | MISC | github.com | Exploit, Patch, Third Party Advisory |
| Download Dependencies over HTTPS by JLLeitschuh · Pull Request #36 · arrow-kt/ank · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Fix some http vulnerabilities · arrow-kt/arrow@74198da · GitHub | MISC | github.com | Patch, Third Party Advisory |
| [CVE-2019-11404][SECURITY] Releases are built/executed/released in the context of insecure/untrusted code · Issue #1310 · arrow-kt/arrow · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| Release Release 0.9.0 · arrow-kt/arrow · GitHub | MISC | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982602 Java (maven) Security Update for io.arrow-kt:arrow-ank-gradle (GHSA-rcj2-vvjx-87pm)