Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2023-4218
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
XXE in eclipse.platform / Eclipse IDE
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Eclipse IDE 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Eclipse IDE是加拿大Eclipse基金会的一个跨平台开源集成开发环境。 Eclipse IDE 2023-09 (4.29) 之前版本存在安全漏洞,该漏洞源于某些包含 xml 内容的文件在解析时容易受到各种XML外部实体注入攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Eclipse FoundationEclipse IDE 0 ~ 4.29 -
Eclipse FoundationEclipse IDE 0 ~ 2023-09 -
Eclipse Foundationorg.eclipse.core.runtime 0 ~ 3.29.0 -
Eclipse Foundationorg.eclipse.pde 0 ~ 3.13.2400 -
II. Public POCs for CVE-2023-4218
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2023-4218
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2023-4218

No comments yet


Leave a comment