Insecure Dependency Resolution in OpenAPI Generator
CVE-2019-11405

8.1HIGH

Key Information:

Vendor
CVE Published:
22 April 2019

What is CVE-2019-11405?

The OpenAPI Generator prior to version 4.0.0-20190419.052012-560 exposes a vulnerability by employing insecure HTTP URLs within configuration files such as build.gradle, build.gradle.mustache, and build.sbt. This practice can lead to the predictable risk of insecurely resolved dependencies, potentially allowing malicious actors to exploit gaps in the dependency chain.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.