Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd2eHYtNWZwMi0zNThx
Incorrect Resource Transfer Between Spheres in eclipse-wtp
In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts that were produced. In case that any of these artifacts were compromised, any developers using these could be altered. Note: In order to validate that this artifact was not compromised, the maintainer would need to confirm that none of the artifacts published to the registry were not altered with. Until this happens, we can not guarantee that this artifact was not compromised even though the probability that this happened is low.
Permalink: https://github.com/advisories/GHSA-gvxv-5fp2-358qJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd2eHYtNWZwMi0zNThx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 5 years ago
Updated: almost 2 years ago
CVSS Score: 5.9
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Percentage: 0.00065
EPSS Percentile: 0.29523
Identifiers: GHSA-gvxv-5fp2-358q, CVE-2019-10753
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10753
- https://snyk.io/vuln/SNYK-JAVA-COMDIFFPLUGSPOTLESS-460377
- https://github.com/diffplug/spotless/issues/360
- https://github.com/advisories/GHSA-gvxv-5fp2-358q
Blast Radius: 4.1
Affected Packages
maven:com.diffplug.spotless:spotless-eclipse-groovy
Dependent packages: 0Dependent repositories: 0
Downloads:
Affected Version Ranges: < 3.0.1
Fixed in: 3.0.1
All affected versions: 2.9.2, 3.0.0
All unaffected versions: 3.0.1, 3.2.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.8.1, 3.9.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0
maven:com.diffplug.spotless:spotless-eclipse-cdt
Dependent packages: 3Dependent repositories: 5
Downloads:
Affected Version Ranges: < 9.4.4
Fixed in: 9.4.4
All affected versions: 9.4.3
All unaffected versions: 9.4.4, 9.4.5, 9.7.0, 9.8.0, 9.8.1, 9.9.0, 9.10.0, 9.11.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.4.0, 10.5.0
maven:com.diffplug.spotless:spotless-eclipse-wtp
Dependent packages: 0Dependent repositories: 1
Downloads:
Affected Version Ranges: < 3.9.6
Fixed in: 3.9.6
All affected versions: 3.9.5
All unaffected versions: 3.9.6, 3.9.7, 3.9.8, 3.10.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.20.0, 3.21.0, 3.22.0, 3.23.0