ZeroHour

CVE-2019-10248

CVSS 3.0
8.1 high
EPSS
<1%p37
Published
()
Modified
Description

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

Vendors
eclipse
Products
vorto
Weakness
CWE-494, CWE-829, CWE-669
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.