Inclusion of Functionality from Untrusted Control Sphere in Eclipse Buildship - CVE-2019-11770
Published: January 13, 2020
Eclipse Buildship
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected project is resolving dependencies over HTTP instead of HTTPS. A remote attacker in the man-in-the-middle position can maliciously compromise any of these artifacts and infect the build artifacts that were produced.