CVE-2019-1000014: High severity erlang rebar3 vulnerability
Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Package modifications not detected, allowing code execution. This attack appears to be exploitable via Victim fetches packages from malicious/compromised mirror. This vulnerability appears to have been fixed in 3.8.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1000014?
CVE-2019-1000014 is rated as a critical severity vulnerability due to the potential for code execution.
How do I fix CVE-2019-1000014?
To fix CVE-2019-1000014, upgrade Erlang/OTP Rebar3 to version 3.7.6 or later.
What causes CVE-2019-1000014?
CVE-2019-1000014 is caused by a Signing oracle vulnerability in the package registry verification process.
Who is affected by CVE-2019-1000014?
Erlang/OTP Rebar3 versions 3.7.0 through 3.7.5 are affected by CVE-2019-1000014.
Can CVE-2019-1000014 be exploited?
Yes, CVE-2019-1000014 can be exploited when a victim fetches packages from a malicious or compromised mirror.