CVE-2023-4218 | In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
- 🔗 gitlab.eclipse.org/security/vulnerability-reports/-/issues/8
- 🔗 github.com/eclipse-pde/eclipse.pde/pull/632/
- 🔗 github.com/eclipse-pde/eclipse.pde/pull/667/
- 🔗 github.com/eclipse-platform/eclipse.platform/pull/76…
- 🔗 github.com/eclipse-platform/eclipse.platform.releng.…
- 🔗 github.com/eclipse-platform/eclipse.platform.ui/comm…
- 🔗 github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1…
- 🔗 github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-15 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2023-4218 | In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for revi