QID 983480

QID 983480: Java (maven) Security Update for org.eclipse.hawkbit:hawkbit-boot-starter-ddi-api (GHSA-jwqm-c9f2-2cq3)

Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to GHSA-jwqm-c9f2-2cq3 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 983480

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-autoconfigure URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-boot-starter URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-boot-starter-ddi-api URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-boot-starter-dmf-api URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-boot-starter-mgmt-api URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-boot-starter-mgmt-ui URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-parent URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-starters URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-ui URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3
    GHSA-jwqm-c9f2-2cq3 org.eclipse.hawkbit:hawkbit-update-server URL Logo github.com/advisories/GHSA-jwqm-c9f2-2cq3