QID 996125
Date Published: 2023-12-04
QID 996125: Java (Maven) Security Update for org.eclipse.core:org.eclipse.core.runtime (GHSA-j24h-xcpc-9jw8)
xml files like ".project" are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-j24h-xcpc-9jw8 for updates and patch information.
Vendor References
- GHSA-j24h-xcpc-9jw8 -
github.com/advisories/GHSA-j24h-xcpc-9jw8
CVEs related to QID 996125
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j24h-xcpc-9jw8 | org.eclipse.core:org.eclipse.core.runtime |
|