Description
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Remediation
References
https://github.com/OpenAPITools/openapi-generator/issues/2253
https://github.com/OpenAPITools/openapi-generator/pull/2248
https://github.com/OpenAPITools/openapi-generator/pull/2697
Related Vulnerabilities
CVE-2021-26541 Vulnerability in npm package gitlog
CVE-2019-20444 Vulnerability in maven package io.netty:netty-all
CVE-2021-41151 Vulnerability in npm package @backstage/plugin-scaffolder-backend
CVE-2022-31179 Vulnerability in npm package shescape
CVE-2022-37767 Vulnerability in maven package io.pebbletemplates:pebble