CVE-2021-32700 affects Ballerina versions 1.2.x and SwanLake alpha3, allowing a supply chain attack where unencrypted HTTP connections and ignored certificate checks enable a Man-in-the-Middle (MiTM) attacker to inject malicious code into Ballerina executables. This vulnerability carries a CVSS score of 7.4 (High), indicating a high potential for impact on confidentiality and integrity with high attack complexity, as it can be exploited remotely without user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage surrounding this CVE. The issue has been patched in Ballerina 1.2.14 and SwanLake alpha4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.14CPE matchmatch criteria | cpe:2.3:a:ballerina:ballerina:*:*:*:*:*:*:*:* | ||
alpha1CPE matchmatch criteria | cpe:2.3:a:ballerina:swan_lake:alpha1:*:*:*:*:*:*:* | ||
alpha2CPE matchmatch criteria | cpe:2.3:a:ballerina:swan_lake:alpha2:*:*:*:*:*:*:* | ||
alpha3CPE matchmatch criteria | cpe:2.3:a:ballerina:swan_lake:alpha3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.