CVE-2019-10248

Source
https://cve.org/CVERecord?id=CVE-2019-10248
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10248.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-10248
Aliases
Published
2019-04-22T21:29:00.257Z
Modified
2026-03-14T09:32:22.312736Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.

References

Affected packages

Git / github.com/eclipse/vorto

Affected ranges

Type
GIT
Repo
https://github.com/eclipse/vorto
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.11"
        }
    ]
}

Affected versions

0.*
0.10.0
0.10.0.M1
0.10.0.M10
0.10.0.M11
0.10.0.M2
0.10.0.M3
0.10.0.M4
0.10.0.M5
0.10.0.M6
0.10.0.M7
0.10.0.M8
0.10.0.M9
0.10.1
0.4.0_M1
0.4.0_M2
0.4.0_M3
0.4.0_M4
0.9.0.RELEASE
0.9.0_M1
0.9.0_M2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10248.json"