Description
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546996
https://github.com/eclipse/xtext-xtend/issues/759
Related Vulnerabilities
CVE-2023-33948 Vulnerability in maven package com.liferay.portal:release.portal.bom
CVE-2022-26049 Vulnerability in maven package com.diffplug.gradle:goomph
CVE-2020-6426 Vulnerability in npm package electron
CVE-2022-45206 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2023-31417 Vulnerability in maven package org.elasticsearch:elasticsearch