VYPR
Unrated severityNVD Advisory· Published Apr 25, 2019· Updated Sep 17, 2024

Java Projects using HTTP to fetch dependencies

CVE-2019-3801

Description

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.

Affected products

4
  • Cloud Foundry/CredHubv5
    Range: 2.1
  • Cloud Foundry/UAA Release (OSS)v5
    Range: All
  • Pivotal/UAA Release (LTS)v5
    Range: v60

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.