Description
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546622
Related Vulnerabilities
CVE-2022-45384 Vulnerability in maven package org.jenkins-ci.plugins:reverse-proxy-auth-plugin
CVE-2021-29480 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2018-11698 Vulnerability in npm package node-sass
CVE-2021-23386 Vulnerability in npm package dns-packet
CVE-2017-2652 Vulnerability in maven package org.jvnet.hudson.plugins:distfork