PT-2019-11658 · Eclipse · Xtend+1

Jl Leitschuh

·

Published

2019-05-06

·

Updated

2022-05-24

·

CVE-2019-10249

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Xtext & Xtend versions prior to 2.18.0
Description: The issue concerns the use of HTTP instead of HTTPS for file transfer during the build process of Xtext & Xtend, potentially compromising built artifacts.
Recommendations: For versions prior to 2.18.0, update to version 2.18.0 or later to resolve the issue.

Exploit

Fix

Improper Encoding or Escaping of Output

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10249
GHSA-RFJ2-4G26-7JW5

Affected Products

Xtend
X/Text