Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cc4w-3cff-j8fw

Опубликовано: 09 нояб. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Duplicate Advisory: Eclipse IDE XXE in eclipse.platform

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-j24h-xcpc-9jw8. This link is maintained to preserve external references.

Original Description

In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).

Пакеты

Наименование

org.eclipse.platform:eclipse.platform

maven
Затронутые версииВерсия исправления

< 4.29

4.29

5 Medium

CVSS3

Дефекты

CWE-611

5 Medium

CVSS3

Дефекты

CWE-611