5
CVSSv3

CVE-2023-4218

Published: 09/11/2023 Updated: 24/11/2023
CVSS v3 Base Score: 5 | Impact Score: 3.6 | Exploitability Score: 1.3
VMScore: 0

Vulnerability Summary

In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).

Vulnerable Product Search on Vulmon Subscribe to Product

eclipse eclipse ide

eclipse pde

eclipse org.eclipse.core.runtime

Github Repositories

SootUp Issues: No Tutorials for beginners cannot find below dependency comgithubsoot-ossSootUp sootup develop-SNAPSHOT Warning:(60, 5) Provides transitive vulnerable dependency maven:orgeclipseplatform:orgeclipsecoreresources:3140 CVE-2023-4218 50 Improper Restriction of XML External Entity Reference vulnerability with Medium severity found Resul