Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

eclipse — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting eclipse. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Eclipse serves as a comprehensive integrated development environment (IDE) primarily used for software development across multiple programming languages. Historically, it has been susceptible to various vulnerability classes, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from its extensive plugin architecture and complex codebase. Security researchers have identified over 14 CVEs, with notable incidents involving insecure deserialization flaws and improper input validation in core components. Its modular nature, while providing flexibility, introduces potential attack surfaces through third-party extensions. Regular security updates are essential for maintaining secure development environments using this platform.

CVE ID Title CVSS Severity Published
CVE-2023-54344 Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console — Equinox OSGi CWE-306 9.8 Critical 2026-05-05
CVE-2023-54342 Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution — Equinox OSGi CWE-306 9.8 Critical 2026-05-05
CVE-2023-5632 Unconditionally adding an event to the epoll causes excessive CPU consumption — Mosquitto CWE-834 7.5 High 2023-10-18
CVE-2023-36478 HTTP/2 HPACK integer overflow and buffer allocation — jetty.project CWE-190 7.5 High 2023-10-10
CVE-2023-3592 Eclipse Mosquitto 安全漏洞 — Mosquitto CWE-401 5.8 Medium 2023-10-02
CVE-2023-0809 Eclipse Mosquitto 安全漏洞 — Mosquitto CWE-789 5.8 Medium 2023-10-02
CVE-2023-41900 Jetty's OpenId Revoked authentication allows one request — jetty.project CWE-1390 3.5 Low 2023-09-15
CVE-2023-40167 Jetty accepts "+" prefixed value in Content-Length — jetty.project CWE-130 5.3 Medium 2023-09-15
CVE-2023-36479 Jetty vulnerable to errant command quoting in CGI Servlet — jetty.project CWE-149 3.5 Low 2023-09-15
CVE-2023-26049 Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty — jetty.project CWE-200 2.4 Low 2023-04-18
CVE-2023-26048 OutOfMemoryError for large multipart without filename in Eclipse Jetty — jetty.project CWE-400 5.3 Medium 2023-04-18
CVE-2022-36022 Some Deeplearning4J packages use unclaimed s3 bucket in tests and examples — deeplearning4j CWE-344 5.3 Medium 2022-11-10
CVE-2021-38443 Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure — CycloneDDS CWE-228 6.6 Medium 2022-05-05
CVE-2021-38441 Eclipse CycloneDDS Write-what-where Condition — CycloneDDS CWE-123 6.6 Medium 2022-05-05
CVE-2021-32835 Groovy Sandbox escape in Eclipse Keti — keti CWE-693 9.9 - 2021-09-09
CVE-2021-32834 Arbitrary Groovy script evaluation in Eclipse Keti — keti CWE-94 8.2 High 2021-09-09

This page lists every published CVE security advisory associated with eclipse. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.