First published: Sun Apr 21 2019(Updated: )
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm | <4.0.0-20190419.052012-560 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11405 is classified as high due to insecurely resolved dependencies.
To fix CVE-2019-11405, upgrade OpenAPI Generator to version 4.0.0-20190419.052012-560 or later.
CVE-2019-11405 may lead to the use of vulnerable dependencies because of HTTP URLs being used in configuration files.
OpenAPI Generator versions prior to 4.0.0-20190419.052012-560 are affected by CVE-2019-11405.
CVE-2019-11405 is primarily a local vulnerability that can be exploited during the build process of applications.