"TITLE":"Java Projects using HTTP to fetch dependencies"
},
"source":{
"discovery":"UNKNOWN"
},
"affects":{
"vendor":{
"vendor_data":[
{
"product":{
"product_data":[
{
"product_name":"CredHub",
"version":{
"version_data":[
{
"affected":"<",
"version_name":"2.1",
"version_value":"2.1.3"
},
{
"affected":"<",
"version_name":"1.9",
"version_value":"1.9.10"
}
]
}
},
{
"product_name":"UAA Release (OSS)",
"version":{
"version_data":[
{
"affected":"<",
"version_name":"All",
"version_value":"v64.0"
}
]
}
},
{
"product_name":"cf-deployment",
"version":{
"version_data":[
{
"affected":"<",
"version_name":"All",
"version_value":"v7.9.0"
}
]
}
}
]
},
"vendor_name":"Cloud Foundry"
},
{
"product":{
"product_data":[
{
"product_name":"UAA Release (LTS)",
"version":{
"version_data":[
{
"affected":"<",
"version_name":"v60",
"version_value":"v60.2"
},
{
"affected":"<",
"version_name":"v64",
"version_value":"v64.1"
}
]
}
}
]
},
"vendor_name":"Pivotal"
}
]
}
},
"description":{
"description_data":[
{
"lang":"eng",
"value":"Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-494: Download of Code Without Integrity Check"