maven package report

Is com.diffplug.spotless:spotless-eclipse-wtp safe?

1 known vulnerability, worst severity MODERATE.

cvss
5.0

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-gvxv-5fp2-358q, the advisory selected below

// advisories

GHSA-gvxv-5fp2-358q

MODERATECVE-2019-10753

In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have perform a Man-in-the-Middle attack during the build and alter the build artifacts t

Affected
< 3.9.6
Fixed in
3.9.6
Weakness
CWE-669
Published
2019-09-11
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:29 UTC. The most recent advisory here was published 2019-09-11. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is com.diffplug.spotless:spotless-eclipse-wtp safe? maven package security report | CyberXYZ