All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.eclipse.xtext:org.eclipse.xtext(Maven) | 0 | 2.18.0 | N/A |
| org.eclipse.xtend:org.eclipse.xtend.core(Maven) | 0 | 2.18.0 | N/A |
CVSS Metrics