Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wm24-pc4h-hw9q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

EPSS

Процентиль: 38%
0.00165
Низкий

7.1 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
redhat
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
nvd
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
debian
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (20 ...

EPSS

Процентиль: 38%
0.00165
Низкий

7.1 High

CVSS3

Дефекты

CWE-611