Man-in-the-Middle Vulnerability in Eclipse HawkBit UI by Eclipse
CVE-2019-10240
8.1HIGH
What is CVE-2019-10240?
Eclipse HawkBit versions prior to 0.3.0M2 are susceptible to a security vulnerability wherein Maven build artifacts for the Vaadin-based user interface were resolved over HTTP instead of the secure HTTPS protocol. This oversight opens the door for malicious entities to launch man-in-the-middle (MITM) attacks, potentially compromising dependent artifacts and resulting in the production of infected build artifacts. Users of affected versions should ensure they upgrade to mitigate these risks.
Affected Version(s)
Eclipse hawkBit < 0.3.0M2