Description
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3767 | Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected. |
Github GHSA |
GHSA-fg2q-v428-2gph | Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS |
References
| Link | Providers |
|---|---|
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=546622 |
|
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-04T22:17:20.094Z
Reserved: 2019-03-27T00:00:00.000Z
Link: CVE-2019-10248
No data.
Status : Modified
Published: 2019-04-22T21:29:00.257
Modified: 2024-11-21T04:18:44.560
Link: CVE-2019-10248
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA