Description
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546996
https://github.com/eclipse/xtext-xtend/issues/759
Related Vulnerabilities
CVE-2018-20676 Vulnerability in npm package bootstrap-sass
CVE-2023-50449 Vulnerability in maven package com.jfinal:jfinal
CVE-2022-21231 Vulnerability in npm package deep-get-set
CVE-2023-46998 Vulnerability in maven package org.webjars.bower:bootbox
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement