arrow-kt Arrow before 0.9.0 resolved Gradle build artifacts (for compiling and building the published JARs) over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by an MITM attack.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://github.com/arrow-kt/arrow/issues/1310 | third party advisory exploit |
https://github.com/arrow-kt/arrow/commit/74198dab522393487d5344f194dc21208ab71ae8 | third party advisory patch |
https://github.com/arrow-kt/arrow/releases/tag/0.9.0 | third party advisory release notes |
https://github.com/arrow-kt/ank/issues/35 | patch third party advisory exploit |
https://github.com/arrow-kt/ank/pull/36 | third party advisory patch |