Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.
References
Link | Resource |
---|---|
https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169 | Permissions Required Vendor Advisory |
https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/ | Exploit Technical Description Third Party Advisory |
https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169 | Permissions Required Vendor Advisory |
https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/ | Exploit Technical Description Third Party Advisory |
Configurations
History
21 Nov 2024, 03:33
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.eclipse.org/bugs/show_bug.cgi?id=519169 - Permissions Required, Vendor Advisory | |
References | () https://research.checkpoint.com/parsedroid-targeting-android-development-research-community/ - Exploit, Technical Description, Third Party Advisory |
Information
Published : 2018-04-20 19:29
Updated : 2024-11-21 03:33
NVD link : CVE-2017-8315
Mitre link : CVE-2017-8315
CVE.ORG link : CVE-2017-8315
JSON object : View
Products Affected
eclipse
- ide
CWE
CWE-611
Improper Restriction of XML External Entity Reference