PT-2020-9930 · Eclipse · Eclipse Web Tools Platform
David Dworken
+1
·
Published
2020-07-15
·
Updated
2023-01-27
·
CVE-2019-17637
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Web Tools Platform versions prior to 3.18 (2020-06)
Description
The issue allows XML and DTD files referring to external entities to be exploited, sending the contents of local files to a remote server when edited or validated. This can occur even when external entity resolution is disabled in the user preferences.
Recommendations
For Eclipse Web Tools Platform versions prior to 3.18 (2020-06), consider updating to a version newer than 3.18 (2020-06) to resolve the issue. As a temporary workaround, restrict the editing and validation of XML and DTD files that refer to external entities to minimize the risk of exploitation.
Exploit
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Web Tools Platform