Description
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Remediation
References
https://github.com/OpenAPITools/openapi-generator/issues/2253
https://github.com/OpenAPITools/openapi-generator/pull/2248
https://github.com/OpenAPITools/openapi-generator/pull/2697
Related Vulnerabilities
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2022-31110 Vulnerability in npm package rsshub
CVE-2021-21295 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2020-11620 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind