Description
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546622
Related Vulnerabilities
CVE-2018-20834 Vulnerability in npm package tar
CVE-2019-10795 Vulnerability in maven package org.webjars.npm:undefsafe
CVE-2020-7672 Vulnerability in npm package mosc
CVE-2020-35149 Vulnerability in maven package org.webjars.npm:mquery
CVE-2022-23617 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore