{"id":"CVE-2023-4218","aliases":["GHSA-j24h-xcpc-9jw8"],"url":"https://o3.security/vulnerability/CVE-2023-4218","summary":"XXE in eclipse.platform / Eclipse IDE","details":"In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).\n","published":"2023-11-09T08:26:51.567Z","modified":"2026-08-12T14:51:18.961957Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.core.runtime","fixedVersion":"3.29.0"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.platform","fixedVersion":"4.29.0"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.jface","fixedVersion":"3.31.0"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.ui.forms","fixedVersion":"3.13.0"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.ui.ide","fixedVersion":"3.21.100"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.ui.workbench","fixedVersion":"3.130.0"},{"ecosystem":"Maven","name":"org.eclipse.platform:org.eclipse.urischeme","fixedVersion":"1.3.100"},{"ecosystem":"Maven","name":"org.eclipse.jdt:org.eclipse.jdt.ui","fixedVersion":"3.30.0"}],"fix":{"url":"https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b","label":"eclipse-cdt/cdt@c7169b3"},"references":[{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/632/"},{"type":"WEB","url":"https://github.com/eclipse-pde/eclipse.pde/pull/667/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4218.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4218"},{"type":"REPORT","url":"https://github.com/eclipse-emf/org.eclipse.emf/issues/10"},{"type":"REPORT","url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/issues/8"},{"type":"FIX","url":"https://github.com/eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b"},{"type":"FIX","url":"https://github.com/eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d"},{"type":"FIX","url":"https://github.com/eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec"},{"type":"FIX","url":"https://github.com/eclipse-platform/eclipse.platform.releng.buildtools/pull/45"},{"type":"FIX","url":"https://github.com/eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba"},{"type":"FIX","url":"https://github.com/eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd"},{"type":"FIX","url":"https://github.com/eclipse-platform/eclipse.platform/pull/761"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T14:51:18.961957Z"}}