QID 980892
QID 980892: Java (maven) Security Update for com.github.shyiko.ktlint:ktlint-core (GHSA-r8h9-hq9c-2p5c)
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r8h9-hq9c-2p5c for updates pertaining to this vulnerability.
Vendor References
- GHSA-r8h9-hq9c-2p5c -
github.com/advisories/GHSA-r8h9-hq9c-2p5c
CVEs related to QID 980892
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r8h9-hq9c-2p5c | com.github.shyiko.ktlint:ktlint-core |
|