CVE-2019-11404
Estado: ModificadaMedia (5.9)—
arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.14%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-311
Referencias
- https://github.com/arrow-kt/ank/issues/35
- https://github.com/arrow-kt/ank/pull/36
- https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8
- https://github.com/arrow-kt/arrow/issues/1310
- https://github.com/arrow-kt/arrow/releases/tag/0.9.0
- https://github.com/arrow-kt/ank/issues/35
- https://github.com/arrow-kt/ank/pull/36
- https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8
- https://github.com/arrow-kt/arrow/issues/1310
- https://github.com/arrow-kt/arrow/releases/tag/0.9.0
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-11404",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "cve@mitre.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.1,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-04-22T11:29:04.580",
"references": [
{
"url": "https://github.com/arrow-kt/ank/issues/35",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/arrow-kt/ank/pull/36",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/arrow-kt/arrow/issues/1310",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/arrow-kt/arrow/releases/tag/0.9.0",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/arrow-kt/ank/issues/35",
"tags": [
"Exploit",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/arrow-kt/ank/pull/36",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/arrow-kt/arrow/issues/1310",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/arrow-kt/arrow/releases/tag/0.9.0",
"tags": [
"Release Notes",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-311"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack."
},
{
"lang": "es",
"value": "arrow-KT Arrow anterior a la versión 0.9.0 resolvió los artefactos de compilación de Gradle (para compilar y construir los Jars publicados) a través de HTTP en lugar de HTTPS. Cualquiera de estos artefactos dependientes podría haber sido maliciosamente comprometido por un ataque MITM."
}
],
"lastModified": "2026-06-17T02:12:51.637",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:arrow-kt:arrow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70E9185C-2AB7-4DE7-832E-C7F04B898592",
"versionEndExcluding": "0.9.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}