SB2019052805 - Inclusion of functionality from untrusted control sphere in Eclipse Buildship
Published: May 28, 2019 Updated: January 13, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inclusion of Functionality from Untrusted Control Sphere (CVE-ID: CVE-2019-11770)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected project is resolving dependencies over HTTP instead of HTTPS. A remote attacker in the man-in-the-middle position can maliciously compromise any of these artifacts and infect the build artifacts that were produced.
Remediation
Install update from vendor's website.