CVE-2023-6194

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
References
Link Resource
https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 Exploit Issue Tracking Patch Vendor Advisory
https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 Exploit Issue Tracking Vendor Advisory
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:memory_analyzer:*:*:*:*:*:*:*:*

History

13 Dec 2023, 22:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CWE CWE-611
CPE cpe:2.3:a:eclipse:memory_analyzer:*:*:*:*:*:*:*:*
References () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 - () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 - Exploit, Issue Tracking, Vendor Advisory
References () https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 - () https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 - () https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 - Exploit, Issue Tracking, Vendor Advisory

11 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-11 14:15

Updated : 2024-02-05 00:22


NVD link : CVE-2023-6194

Mitre link : CVE-2023-6194

CVE.ORG link : CVE-2023-6194


JSON object : View

Products Affected

eclipse

  • memory_analyzer
CWE
CWE-611

Improper Restriction of XML External Entity Reference