{"id":"GHSA-cc4w-3cff-j8fw","summary":"Duplicate Advisory: Eclipse IDE XXE in eclipse.platform","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-j24h-xcpc-9jw8. This link is maintained to preserve external references.\n\n## Original Description\nIn Eclipse IDE versions \u003c 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).\n","modified":"2023-11-30T19:52:20Z","published":"2023-11-09T09:30:26Z","withdrawn":"2023-11-30T19:52:20Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-11-30T19:52:20Z","nvd_published_at":"2023-11-09T09:15:08Z","cwe_ids":["CWE-611"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4218"},{"type":"WEB","url":"https://github.com/eclipse-emf/org.eclipse.emf/issues/10"},{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/632"},{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/667"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform/pull/761"},{"type":"WEB","url":"https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b"},{"type":"WEB","url":"https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d"},{"type":"WEB","url":"https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba"},{"type":"WEB","url":"https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8"}],"affected":[{"package":{"name":"org.eclipse.platform:eclipse.platform","ecosystem":"Maven","purl":"pkg:maven/org.eclipse.platform/eclipse.platform"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.29"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/11/GHSA-cc4w-3cff-j8fw/GHSA-cc4w-3cff-j8fw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}