Description
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2980 | In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch). |
Github GHSA |
GHSA-j24h-xcpc-9jw8 | Eclipse IDE XXE in eclipse.platform |
References
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-09-03T19:26:14.225Z
Reserved: 2023-08-08T06:06:20.616Z
Link: CVE-2023-4218
Updated: 2024-08-02T07:17:12.212Z
Status : Modified
Published: 2023-11-09T09:15:08.320
Modified: 2024-11-21T08:34:38.737
Link: CVE-2023-4218
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA