Open mend-bolt-for-github[bot] opened 2 years ago
Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard
Library home page: http://checkstyle.sourceforge.net/
Path to dependency file: /build.gradle
Path to vulnerable library: /.gradle/caches/modules-2/files-2.1/com.puppycrawl.tools/checkstyle/8.7/175736b87b0aa168c2db773f4f27df71edb46458/checkstyle-8.7.jar
Dependency Hierarchy: - :x: **checkstyle-8.7.jar** (Vulnerable Library)
Found in HEAD commit: 722089816e5192b667c19cb836256ef6da8be1ac
Found in base branch: master
Checkstyle before 8.18 loads external DTDs by default.
Publish Date: 2019-03-11
URL: CVE-2019-9658
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: None - Availability Impact: None
Type: Upgrade version
Release Date: 2019-03-11
Fix Resolution: 8.18
Step up your Open Source Security Game with Mend here
CVE-2019-9658 - Medium Severity Vulnerability
Vulnerable Library - checkstyle-8.7.jar
Checkstyle is a development tool to help programmers write Java code that adheres to a coding standard
Library home page: http://checkstyle.sourceforge.net/
Path to dependency file: /build.gradle
Path to vulnerable library: /.gradle/caches/modules-2/files-2.1/com.puppycrawl.tools/checkstyle/8.7/175736b87b0aa168c2db773f4f27df71edb46458/checkstyle-8.7.jar
Dependency Hierarchy: - :x: **checkstyle-8.7.jar** (Vulnerable Library)
Found in HEAD commit: 722089816e5192b667c19cb836256ef6da8be1ac
Found in base branch: master
Vulnerability Details
Checkstyle before 8.18 loads external DTDs by default.
Publish Date: 2019-03-11
URL: CVE-2019-9658
CVSS 3 Score Details (5.3)
Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: None - Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2019-03-11
Fix Resolution: 8.18
Step up your Open Source Security Game with Mend here