Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2019-10248

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.6%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2019-10248
  • Eclipse » Vorto » Version: N/A
    cpe:2.3:a:eclipse:vorto:-
  • Eclipse » Vorto » Version: 0.10.0
    cpe:2.3:a:eclipse:vorto:0.10.0
  • Eclipse » Vorto » Version: 0.10.1
    cpe:2.3:a:eclipse:vorto:0.10.1
  • Eclipse » Vorto » Version: 0.4.0
    cpe:2.3:a:eclipse:vorto:0.4.0
  • Eclipse » Vorto » Version: 0.9.0
    cpe:2.3:a:eclipse:vorto:0.9.0


Contact Us

Shodan ® - All rights reserved