In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: eclipse
Published: 2023-12-11T14:04:51.680Z
Updated: 2024-08-02T08:21:17.798Z
Reserved: 2023-11-17T16:32:44.668Z
Link: CVE-2023-6194
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-11T14:15:31.847
Modified: 2024-11-21T08:43:19.773
Link: CVE-2023-6194
Redhat
No data.