{"id":"GHSA-r8h9-hq9c-2p5c","summary":"High severity vulnerability that affects com.github.shyiko.ktlint:ktlint-core","details":"Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.","aliases":["CVE-2019-1010260"],"modified":"2023-11-08T04:00:41.086327Z","published":"2019-04-08T15:18:54Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:54:05Z","nvd_published_at":null,"cwe_ids":["CWE-319"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010260"},{"type":"WEB","url":"https://github.com/shyiko/ktlint/pull/332"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r8h9-hq9c-2p5c"},{"type":"PACKAGE","url":"https://github.com/shyiko/ktlint"}],"affected":[{"package":{"name":"com.github.shyiko.ktlint:ktlint-core","ecosystem":"Maven","purl":"pkg:maven/com.github.shyiko.ktlint/ktlint-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.30.0"}]}],"versions":["0.10.0","0.10.1","0.10.2","0.11.0","0.11.1","0.12.0","0.12.1","0.13.0","0.14.0","0.15.0","0.15.1","0.16.0","0.16.1","0.17.0","0.17.1","0.18.0","0.19.0","0.2.0","0.2.1","0.2.2","0.20.0","0.21.0","0.22.0","0.23.0","0.23.1","0.24.0","0.25.0","0.25.1","0.26.0","0.27.0","0.28.0","0.29.0","0.3.0","0.3.1","0.4.0","0.5.0","0.5.1","0.6.0","0.6.1","0.6.2","0.7.0","0.7.1","0.8.0","0.8.1","0.8.2","0.8.3","0.9.0","0.9.1","0.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/04/GHSA-r8h9-hq9c-2p5c/GHSA-r8h9-hq9c-2p5c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}