Description
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546996
https://github.com/eclipse/xtext-xtend/issues/759
Related Vulnerabilities
CVE-2020-36185 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2016-10735 Vulnerability in maven package ru.taskurotta:bootstrap
CVE-2016-3737 Vulnerability in maven package org.rhq:rhq-enterprise-comm
CVE-2018-19057 Vulnerability in npm package simplemde
CVE-2020-2303 Vulnerability in maven package org.jenkins-ci.plugins:active-directory