VYPR
Vendor

Diffplug

Products
7
CVEs
3
Across products
7
Status
Private

Products

7

Recent CVEs

3
  • CVE-2019-10753MedSep 5, 2019
    risk 0.38cvss 5.9epss 0.01

    In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure…

  • CVE-2022-26049MedSep 11, 2022
    risk 0.28cvss 5.3epss 0.02

    This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an…

  • CVE-2019-9843HigJun 28, 2019
    risk 0.00cvss 7.5epss 0.01

    In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents…