Vulnerabilities are tracked by the Eclipse security team, in cooperation with the ChemClipse project lead. Fixing vulnerabilities is taken care of by the ChemClipse project committers, with assistance and guidance of the security team.
We recommend that in case of suspected vulnerabilities you do not use the ChemClipse public issue tracker, but instead contact the Eclipse Security Team directly via [email protected].