{"id":"UBUNTU-CVE-2023-4218","details":"In Eclipse IDE versions \u003c 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).","modified":"2025-10-24T05:01:31Z","published":"2023-11-09T09:15:00Z","upstream":["CVE-2023-4218"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4218"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8"},{"type":"REPORT","url":"https://github.com/eclipse-pde/eclipse.pde/pull/632/"},{"type":"REPORT","url":"https://github.com/eclipse-pde/eclipse.pde/pull/667/"},{"type":"REPORT","url":"https://github.com/eclipse-platform/eclipse.platform/pull/761"},{"type":"REPORT","url":"https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45"},{"type":"REPORT","url":"https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd"},{"type":"REPORT","url":"https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec"},{"type":"REPORT","url":"https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d"},{"type":"REPORT","url":"https://github.com/eclipse-emf/org.eclipse.emf/issues/10"},{"type":"REPORT","url":"https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba"},{"type":"REPORT","url":"https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-4218"}],"affected":[{"package":{"name":"eclipse","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/eclipse@3.8.1-8?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.8.1-8"],"ecosystem_specific":{"binaries":[{"binary_version":"3.8.1-8","binary_name":"eclipse"},{"binary_name":"eclipse-jdt","binary_version":"3.8.1-8"},{"binary_name":"eclipse-pde","binary_version":"3.8.1-8"},{"binary_name":"eclipse-platform","binary_version":"3.8.1-8"},{"binary_name":"eclipse-platform-data","binary_version":"3.8.1-8"},{"binary_name":"eclipse-rcp","binary_version":"3.8.1-8"},{"binary_name":"libequinox-osgi-java","binary_version":"3.8.1-8"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4218.json"}},{"package":{"name":"eclipse","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/eclipse@3.8.1-11?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.8.1-10","3.8.1-11"],"ecosystem_specific":{"binaries":[{"binary_name":"eclipse","binary_version":"3.8.1-11"},{"binary_name":"eclipse-jdt","binary_version":"3.8.1-11"},{"binary_name":"eclipse-pde","binary_version":"3.8.1-11"},{"binary_name":"eclipse-platform","binary_version":"3.8.1-11"},{"binary_name":"eclipse-platform-data","binary_version":"3.8.1-11"},{"binary_name":"eclipse-rcp","binary_version":"3.8.1-11"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-4218.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}