Vulnerability CVE-2023-6194


Published: 2023-12-11   Modified: 2023-12-14

Description:
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.

Type:

CWE-611

(Information Exposure Through XML External Entity Reference)

Affected software
Eclipse -> Memory analyzer 

 References:
https://gitlab.eclipse.org/security/cve-assignement/-/issues/15
https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169

Copyright 2024, cxsecurity.com

 

Back to Top