Description
OpenAPI Tools OpenAPI Generator before 4.0.0-20190419.052012-560 uses http:// URLs in various build.gradle, build.gradle.mustache, and build.sbt files, which may have caused insecurely resolved dependencies.
Remediation
References
https://github.com/OpenAPITools/openapi-generator/issues/2253
https://github.com/OpenAPITools/openapi-generator/pull/2248
https://github.com/OpenAPITools/openapi-generator/pull/2697
Related Vulnerabilities
CVE-2021-32854 Vulnerability in maven package org.webjars.npm:textangular
CVE-2021-21364 Vulnerability in maven package io.swagger:swagger-codegen
CVE-2021-44906 Vulnerability in maven package org.webjars.npm:minimist
CVE-2020-7714 Vulnerability in npm package confucious
CVE-2021-26539 Vulnerability in maven package org.webjars.npm:sanitize-html