Skip to content

Potential for a supply chain attack via MiTM against users

High
anupama-pathirage published GHSA-f5qg-fqrw-v5ww Jun 22, 2021

Package

ballerina pull, build, run commands

Affected versions

< 1.2.14, < SL-alpha4

Patched versions

1.2.14, SL-alpha4

Description

Impact

Ballerina versions 1.2.x and SL releases up to alpha 3 have a potential for a supply chain attack via MiTM against users. The vulnerability allows an attacker to substitute or modify packages retrieved from BC thus allowing to inject malicious code into ballerina executables.

Patches

Ballerina 1.2.14
Ballerina SwanLake alpha4

For more information

If you have any questions or comments about this advisory:

  • Email us at security [at] ballerina.io

Severity

High

CVE ID

CVE-2021-32700

Weaknesses

No CWEs

Credits