CVE-2023-6194

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
11/12/2023
Last modified:
13/12/2023

Description

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit<br /> document type definition (DTD) references to external entities.<br /> This means that if a user chooses to use a malicious report definition XML file containing an external entity reference<br /> to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:memory_analyzer:*:*:*:*:*:*:*:* 0.7 (including) 1.14.0 (including)