In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2404-1 eclipse-wtp security update
EUVD EUVD EUVD-2019-7948 In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-05T01:47:13.211Z

Reserved: 2019-10-16T00:00:00

Link: CVE-2019-17637

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-07-15T15:15:11.377

Modified: 2024-11-21T04:32:40.703

Link: CVE-2019-17637

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-07-15T00:00:00Z

Links: CVE-2019-17637 - Bugzilla

cve-icon OpenCVE Enrichment

No data.