CVE-2019-10249

Description

All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.

Risk Information

Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.16

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-10249 are fixed in Eclipse-org.eclipse.xtext 2.18.0Windows
Vulnerabilities CVE-2019-10249 are fixed in Eclipse - org.eclipse.xtend.core 2.18.0Windows
Vulnerabilities CVE-2019-10249 are fixed in Eclipse-org.eclipse.xtext for Linux 2.18.0Linux
Vulnerabilities CVE-2019-10249 are fixed in Eclipse - org.eclipse.xtend.core for Linux 2.18.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234