QID 982602
QID 982602: Java (maven) Security Update for io.arrow-kt:arrow-ank-gradle (GHSA-rcj2-vvjx-87pm)
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rcj2-vvjx-87pm for updates pertaining to this vulnerability.
Vendor References
- GHSA-rcj2-vvjx-87pm -
github.com/advisories/GHSA-rcj2-vvjx-87pm
CVEs related to QID 982602
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rcj2-vvjx-87pm | io.arrow-kt:arrow-ank-gradle |
|