GHSA-rcj2-vvjx-87pm

Suggest an improvement
Source
https://github.com/advisories/GHSA-rcj2-vvjx-87pm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-rcj2-vvjx-87pm/GHSA-rcj2-vvjx-87pm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-rcj2-vvjx-87pm
Aliases
Published
2019-04-22T17:15:40Z
Modified
2023-11-08T04:01:01.578465Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Missing Encryption of Sensitive Data in arrow-kt Arrow
Details

arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.

Database specific
{
    "nvd_published_at": "2019-04-22T11:29:00Z",
    "github_reviewed_at": "2019-04-22T17:15:03Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-311"
    ]
}
References

Affected packages

Maven / io.arrow-kt:arrow-ank-gradle

Package

Name
io.arrow-kt:arrow-ank-gradle
View open source insights on deps.dev
Purl
pkg:maven/io.arrow-kt/arrow-ank-gradle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.0

Affected versions

0.*

0.8.0
0.8.1
0.8.2