OSV 1.4.0 · github-reviewed · 修改于 2021-09-17 22:43
发布时间
2019-04-08 23:18
GitHub 审查时间
2020-06-17 05:54
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/04/GHSA-r8h9-hq9c-2p5c/GHSA-r8h9-hq9c-2p5c.json
Using ktlint to download and execute custom rulesets can result in arbitrary code execution as the served jars can be compromised by a MITM. This attack is exploitable via Man in the Middle of the HTTP connection to the artifact servers. This vulnerability appears to have been fixed in 0.30.0 and later; after commit 5e547b287d6c260d328a2cb658dbe6b7a7ff2261.