In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2980 In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
Github GHSA Github GHSA GHSA-j24h-xcpc-9jw8 Eclipse IDE XXE in eclipse.platform
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-09-03T19:26:14.225Z

Reserved: 2023-08-08T06:06:20.616Z

Link: CVE-2023-4218

cve-icon Vulnrichment

Updated: 2024-08-02T07:17:12.212Z

cve-icon NVD

Status : Modified

Published: 2023-11-09T09:15:08.320

Modified: 2024-11-21T08:34:38.737

Link: CVE-2023-4218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.