CVE-2019-11404 – io.arrow-kt:arrow-ank-gradle
Package
Manager: maven
Name: io.arrow-kt:arrow-ank-gradle
Vulnerable Version: >=0 <0.9.0
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00319 pctl0.54403
Details
Missing Encryption of Sensitive Data in arrow-kt Arrow arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
Metadata
Created: 2019-04-22T17:15:40Z
Modified: 2021-05-11T14:57:28Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-rcj2-vvjx-87pm/GHSA-rcj2-vvjx-87pm.json
CWE IDs: ["CWE-311"]
Alternative ID: GHSA-rcj2-vvjx-87pm
Finding: F020
Auto approve: 1