CVE-2019-11405: High severity npm vulnerability
Published Apr 21, 2019
·Updated
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Affected Software
1 affected component
openapi-generator Openapi generator<4.0.0-20190419.052012-560
Event History
Apr 21, 2019
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2019-11405?
The severity of CVE-2019-11405 is classified as high due to insecurely resolved dependencies.
2
How do I fix CVE-2019-11405?
To fix CVE-2019-11405, upgrade OpenAPI Generator to version 4.0.0-20190419.052012-560 or later.
3
What are the implications of CVE-2019-11405?
CVE-2019-11405 may lead to the use of vulnerable dependencies because of HTTP URLs being used in configuration files.
4
What software is affected by CVE-2019-11405?
OpenAPI Generator versions prior to 4.0.0-20190419.052012-560 are affected by CVE-2019-11405.
5
Is CVE-2019-11405 a remote or local vulnerability?
CVE-2019-11405 is primarily a local vulnerability that can be exploited during the build process of applications.