CVE-2023-6194
CVE-2023-6194
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit
document type definition (DTD) references to external entities.
This means that if a user chooses to use a malicious report definition XML file containing an external entity reference
to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Produtos afetados
Eclipse Foundation · Eclipse Memory Analyzer (tools.mat)Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →