GHSA-gvxv-5fp2-358q
MODERATECVE-2019-10753In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts t
- Affected
- < 3.0.1
- Fixed in
- 3.0.1
- Weakness
- CWE-669
- Published
- 2019-09-11
- Source
- github