logo

CVE-2019-11404 io.arrow-kt:arrow-ank-gradle

Package

Manager: maven
Name: io.arrow-kt:arrow-ank-gradle
Vulnerable Version: >=0 <0.9.0

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00319 pctl0.54403

Details

Missing Encryption of Sensitive Data in arrow-kt Arrow arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.

Metadata

Created: 2019-04-22T17:15:40Z
Modified: 2021-05-11T14:57:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-rcj2-vvjx-87pm/GHSA-rcj2-vvjx-87pm.json
CWE IDs: ["CWE-311"]
Alternative ID: GHSA-rcj2-vvjx-87pm
Finding: F020
Auto approve: 1