Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Use HTTPS to resolve dependencies in Gradle Build #140

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Commits on Jul 21, 2022

  1. vuln-fix: Use HTTPS instead of HTTP to resolve dependencies

    This fixes a security vulnerability in this project where the `build.gradle`
    files were configuring Gradle to resolve dependencies over HTTP instead of
    HTTPS.
    
    Weakness: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
    Severity: High
    CVSSS: 8.1
    Detection: OpenRewrite
    
    Reported-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
    Signed-off-by: Jonathan Leitschuh <Jonathan.Leitschuh@gmail.com>
    
    Bug-tracker: JLLeitschuh/security-research#9
    
    Co-authored-by: Moderne <team@moderne.io>
    JLLeitschuh and TeamModerne committed Jul 21, 2022
    Configuration menu
    Copy the full SHA
    8b94a45 View commit details
    Browse the repository at this point in the history