Vulnerability identifier: #VU86800
Vulnerability risk: Low
CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-4218
CWE-ID:
CWE-611
Exploitation vector: Local
Exploit availability: No
Vulnerable software:
Eclipse IDE for Java
Other software /
Other software solutions
Vendor: Eclipse
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to some files with xml content are parsed vulnerable against all sorts of XXE attacks. A local user can trick the victim into opening a specially crafted XML code and view contents of arbitrary files on the system or initiate requests to external systems.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Eclipse IDE for Java: 4.29
External links
https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8
https://github.com/eclipse-pde/eclipse.pde/pull/632/
https://github.com/eclipse-pde/eclipse.pde/pull/667/
https://github.com/eclipse-platform/eclipse.platform/pull/761
https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45
https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd
https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec
https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d
https://github.com/eclipse-emf/org.eclipse.emf/issues/10
https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba
https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.