VulnerabilityModified
CVE-2019-11404
Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
MEDIUM 5.9EPSS 1.14%
Does this matter?
Lower severity and a low EPSS score (1.14%). Track it; it rarely justifies an emergency change on its own.
Description
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.14% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-311
- Affected
- arrow-kt/arrow
- Source
- cve@mitre.org
References
- https://github.com/arrow-kt/ank/issues/35Exploit, Patch, Third Party Advisory
- https://github.com/arrow-kt/ank/pull/36Patch, Third Party Advisory
- https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8Patch, Third Party Advisory
- https://github.com/arrow-kt/arrow/issues/1310Exploit, Third Party Advisory
- https://github.com/arrow-kt/arrow/releases/tag/0.9.0Release Notes, Third Party Advisory
- https://github.com/arrow-kt/ank/issues/35Exploit, Patch, Third Party Advisory
- https://github.com/arrow-kt/ank/pull/36Patch, Third Party Advisory
- https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8Patch, Third Party Advisory
- https://github.com/arrow-kt/arrow/issues/1310Exploit, Third Party Advisory
- https://github.com/arrow-kt/arrow/releases/tag/0.9.0Release Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.