← Back

CVE-2019-10240

nvd nist
Published: Apr 3, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected.

Affected (2)

Products: Eclipse: Hawkbit
1 product
Hawkbit
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Eclipse
Up to 0.2.5
Version 0.3.0 m1

References (2)

Source: emo@eclipse.org
ExploitIssue TrackingVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingVendor Advisory

Timeline

No history available yet.