Lucene search

K

Diffplug Security Vulnerabilities

cve
cve

CVE-2019-9843

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over both HTTP and HTTPS and didn't respect the resolveExternalEntities setting. For example, this allows disclosure of file contents to a MITM attacker...

7.5CVSS

7.3AI Score

0.002EPSS

2019-06-28 06:15 PM
54
cve
cve

CVE-2022-26049

This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break out of the expected destination directory, writing contents into arbitrary locations on the file system. Overwriting certain files/directories could allow an attacker to achieve...

8.8CVSS

8.9AI Score

0.009EPSS

2022-09-11 02:15 PM
52
15
cve
cve

CVE-2019-10753

In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a...

5.9CVSS

5.6AI Score

0.001EPSS

2019-09-05 08:15 PM
106