arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
References
Link Resource
https://github.com/arrow-kt/ank/issues/35 Exploit Patch Third Party Advisory
https://github.com/arrow-kt/ank/pull/36 Patch Third Party Advisory
https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8 Patch Third Party Advisory
https://github.com/arrow-kt/arrow/issues/1310 Exploit Third Party Advisory
https://github.com/arrow-kt/arrow/releases/tag/0.9.0 Release Notes Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-04-21T16:06:56

Updated: 2019-04-21T16:06:56

Reserved: 2019-04-21T00:00:00


Link: CVE-2019-11404

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-04-22T11:29:04.580

Modified: 2020-08-24T17:37:01.140


Link: CVE-2019-11404

JSON object: View

cve-icon Redhat Information

No data.

CWE