CVE-2019-17637

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
15/07/2020
Last modified:
27/01/2023

Description

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:web_tools_platform:*:*:*:*:*:*:*:* 1.0 (including) 3.18 (including)
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*