{"api_version":"1","generated_at":"2026-07-24T18:24:43+00:00","cve":"CVE-2019-11404","urls":{"html":"https://cve.report/CVE-2019-11404","api":"https://cve.report/api/cve/CVE-2019-11404.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11404","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11404"},"summary":{"title":"CVE-2019-11404","description":"arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-04-22 11:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-311"],"metrics":[],"references":[{"url":"https://github.com/arrow-kt/ank/issues/35","name":"https://github.com/arrow-kt/ank/issues/35","refsource":"MISC","tags":["Exploit","Patch","Third Party Advisory"],"title":"[SECURITY] Releases are built/executed/released in the context of insecure/untrusted code · Issue #35 · arrow-kt/ank · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/arrow-kt/ank/pull/36","name":"https://github.com/arrow-kt/ank/pull/36","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Download Dependencies over HTTPS by JLLeitschuh · Pull Request #36 · arrow-kt/ank · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8","name":"https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Fix some http vulnerabilities · arrow-kt/arrow@74198da · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/arrow-kt/arrow/issues/1310","name":"https://github.com/arrow-kt/arrow/issues/1310","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"[CVE-2019-11404][SECURITY] Releases are built/executed/released in the context of insecure/untrusted code · Issue #1310 · arrow-kt/arrow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/arrow-kt/arrow/releases/tag/0.9.0","name":"https://github.com/arrow-kt/arrow/releases/tag/0.9.0","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Release Release 0.9.0 · arrow-kt/arrow · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11404","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11404","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11404","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"arrow-kt","cpe5":"arrow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11404","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"arrow-kt","cpe5":"arrow","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-11404","qid":"982602","title":"Java (maven) Security Update for io.arrow-kt:arrow-ank-gradle (GHSA-rcj2-vvjx-87pm)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-11404","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/arrow-kt/arrow/issues/1310","refsource":"MISC","name":"https://github.com/arrow-kt/arrow/issues/1310"},{"url":"https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8","refsource":"MISC","name":"https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8"},{"url":"https://github.com/arrow-kt/arrow/releases/tag/0.9.0","refsource":"MISC","name":"https://github.com/arrow-kt/arrow/releases/tag/0.9.0"},{"url":"https://github.com/arrow-kt/ank/issues/35","refsource":"MISC","name":"https://github.com/arrow-kt/ank/issues/35"},{"url":"https://github.com/arrow-kt/ank/pull/36","refsource":"MISC","name":"https://github.com/arrow-kt/ank/pull/36"}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AC:H/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N","version":"3.0"}}},"nvd":{"publishedDate":"2019-04-22 11:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-311"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:arrow-kt:arrow:*:*:*:*:*:*:*:*","versionEndExcluding":"0.9.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11404","Ordinal":"149695","Title":"CVE-2019-11404","CVE":"CVE-2019-11404","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11404","Ordinal":"1","NoteData":"arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11404","Ordinal":"2","NoteData":"2019-04-21","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11404","Ordinal":"3","NoteData":"2019-04-21","Type":"Other","Title":"Modified"}]}}}