Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd2eHYtNWZwMi0zNThx

Incorrect Resource Transfer Between Spheres in eclipse-wtp

In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts that were produced. In case that any of these artifacts were compromised, any developers using these could be altered. Note: In order to validate that this artifact was not compromised, the maintainer would need to confirm that none of the artifacts published to the registry were not altered with. Until this happens, we can not guarantee that this artifact was not compromised even though the probability that this happened is low.

Permalink: https://github.com/advisories/GHSA-gvxv-5fp2-358q
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd2eHYtNWZwMi0zNThx
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 5 years ago
Updated: almost 2 years ago


CVSS Score: 5.9
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Percentage: 0.00065
EPSS Percentile: 0.29523

Identifiers: GHSA-gvxv-5fp2-358q, CVE-2019-10753
References: Repository: https://github.com/diffplug/spotless
Blast Radius: 4.1

Affected Packages

maven:com.diffplug.spotless:spotless-eclipse-groovy
Dependent packages: 0
Dependent repositories: 0
Downloads:
Affected Version Ranges: < 3.0.1
Fixed in: 3.0.1
All affected versions: 2.9.2, 3.0.0
All unaffected versions: 3.0.1, 3.2.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.8.0, 3.8.1, 3.9.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0
maven:com.diffplug.spotless:spotless-eclipse-cdt
Dependent packages: 3
Dependent repositories: 5
Downloads:
Affected Version Ranges: < 9.4.4
Fixed in: 9.4.4
All affected versions: 9.4.3
All unaffected versions: 9.4.4, 9.4.5, 9.7.0, 9.8.0, 9.8.1, 9.9.0, 9.10.0, 9.11.0, 10.0.0, 10.1.0, 10.2.0, 10.3.0, 10.4.0, 10.5.0
maven:com.diffplug.spotless:spotless-eclipse-wtp
Dependent packages: 0
Dependent repositories: 1
Downloads:
Affected Version Ranges: < 3.9.6
Fixed in: 3.9.6
All affected versions: 3.9.5
All unaffected versions: 3.9.6, 3.9.7, 3.9.8, 3.10.0, 3.14.0, 3.15.0, 3.15.1, 3.15.2, 3.15.3, 3.16.0, 3.17.0, 3.18.0, 3.18.1, 3.19.0, 3.20.0, 3.21.0, 3.22.0, 3.23.0