CVE-2019-10249

HIGH

Xtext & Xtend <2.18.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.

References (2)

Core 2
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugs.eclipse.org/bugs/show_bug.cgi?id=546996
Exploit, Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/eclipse/xtext-xtend/issues/759

Scores

CVSS v3 8.1
EPSS 0.0065
EPSS Percentile 45.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-494 CWE-829 CWE-116
Status published
Products (4)
eclipse/xtend < 2.18.0
eclipse/xtext < 2.18.0
org.eclipse.xtend/org.eclipse.xtend.core 0 - 2.18.0Maven
org.eclipse.xtext/org.eclipse.xtext 0 - 2.18.0Maven
Published May 06, 2019
Tracked Since Feb 18, 2026