Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-17637

Опубликовано: 15 июл. 2020
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CodeReady Studio 12org.eclipse.wst.dtd.coreAffected
Red Hat CodeReady Studio 12org.jboss.ide.eclipse.archives.webtoolsAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1857369eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator

EPSS

Процентиль: 38%
0.00165
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
nvd
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

CVSS3: 7.1
debian
больше 5 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (20 ...

CVSS3: 7.1
github
больше 3 лет назад

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

EPSS

Процентиль: 38%
0.00165
Низкий

7.1 High

CVSS3