Description
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2404-1 | eclipse-wtp security update |
EUVD |
EUVD-2019-7948 | In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences. |
References
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T01:47:13.211Z
Reserved: 2019-10-16T00:00:00.000Z
Link: CVE-2019-17637
No data.
Status : Modified
Published: 2020-07-15T15:15:11.377
Modified: 2024-11-21T04:32:40.703
Link: CVE-2019-17637
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD