In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
References
Link | Resource |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 | Exploit Issue Tracking Patch Vendor Advisory |
https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 | Exploit Issue Tracking Vendor Advisory |
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
13 Dec 2023, 22:02
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-11 14:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-6194
Mitre link : CVE-2023-6194
CVE.ORG link : CVE-2023-6194
JSON object : View
Products Affected
eclipse
- memory_analyzer
CWE
CWE-611
Improper Restriction of XML External Entity Reference