Description
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Remediation
References
https://github.com/OpenAPITools/openapi-generator/issues/2253
https://github.com/OpenAPITools/openapi-generator/pull/2248
https://github.com/OpenAPITools/openapi-generator/pull/2697
Related Vulnerabilities
CVE-2020-28424 Vulnerability in npm package s3-kilatstorage
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-48711 Vulnerability in maven package org.webjars.npm:google-translate-api-browser
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-simple-mfa
CVE-2021-46365 Vulnerability in maven package info.magnolia:magnolia-core