CVE-2023-6194

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
References
Link Resource
https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 Exploit Issue Tracking Patch Vendor Advisory
https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 Exploit Issue Tracking Vendor Advisory
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:memory_analyzer:*:*:*:*:*:*:*:*

History

13 Dec 2023, 22:02

Type Values Removed Values Added
First Time Eclipse
Eclipse memory Analyzer
CVSS v2 : unknown
v3 : 2.8
v2 : unknown
v3 : 7.1
Summary
  • (es) En las versiones 0.7 a 1.14.0 de Eclipse Memory Analyzer, los archivos XML de definición de informes no se filtran para prohibir las referencias de definición de tipo de documento (DTD) a entidades externas. Esto significa que si un usuario elige utilizar un archivo XML de definición de informe malicioso que contiene una referencia de entidad externa para generar un informe, Eclipse Memory Analyzer puede acceder a archivos externos o URL definidos mediante una DTD en la definición del informe.
References () https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 - () https://bugs.eclipse.org/bugs/show_bug.cgi?id=582631 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 - () https://gitlab.eclipse.org/security/cve-assignement/-/issues/15 - Exploit, Issue Tracking, Vendor Advisory
References () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 - () https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/169 - Exploit, Issue Tracking, Vendor Advisory
CPE cpe:2.3:a:eclipse:memory_analyzer:*:*:*:*:*:*:*:*

11 Dec 2023, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-11 14:15

Updated : 2023-12-13 22:02


NVD link : CVE-2023-6194

Mitre link : CVE-2023-6194

CVE.ORG link : CVE-2023-6194


JSON object : View

Products Affected

eclipse

  • memory_analyzer
CWE
CWE-611

Improper Restriction of XML External Entity Reference