Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-17637

Опубликовано: 15 июл. 2020
Источник: debian
EPSS Низкий

Описание

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
eclipse-wtpfixed3.18-1package

Примечания

  • https://bugs.eclipse.org/bugs/show_bug.cgi?id=458571

  • http://git.eclipse.org/c/sourceediting/webtools.sourceediting.git/commit/?id=9644d4217cd6e3be367d654a8320104d88ddfd6b

  • Issue fixed along when packaging 3.18 upstream version as in the Debian

  • source (re)packaging the DTDParser.java and DTDValidator.java were removed.

EPSS

Процентиль: 38%
0.00165
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
redhat
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
nvd
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
github
больше 3 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

EPSS

Процентиль: 38%
0.00165
Низкий