In Eclipse Memory Analyzer versions... CVE-2023-6194

- AV AC AU C I A
发布: 2023-12-11
修订: 2023-12-13

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息