CVE-2019-17637
published 2020-07-15CVE-2019-17637: In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the…
PriorityP431high7.1CVSS 3.1
AVLACLPRNUIRSUCHIHAN
EPSS
0.88%
55.4th percentile
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | eclipse-wtp | < eclipse-wtp 3.18-1 (bookworm) | eclipse-wtp 3.18-1 (bookworm) |
| eclipse | web_tools_platform | 1.0 – 3.18 | — |
| the_eclipse_foundation | eclipse_web_tools_platform | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wm24-pc4h-hw9q: In all versions of Eclipse Web Tools Platform through release 3
ghsa_unreviewed·2022-05-24
CVE-2019-17637 [MEDIUM] CWE-611 GHSA-wm24-pc4h-hw9q: In all versions of Eclipse Web Tools Platform through release 3
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
OSV
CVE-2019-17637: In all versions of Eclipse Web Tools Platform through release 3
osv·2020-07-15·CVSS 7.1
CVE-2019-17637 [HIGH] CVE-2019-17637: In all versions of Eclipse Web Tools Platform through release 3
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Debian
CVE-2019-17637: eclipse-wtp - In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XM...
vendor_debian·2019·CVSS 7.1
CVE-2019-17637 [HIGH] CVE-2019-17637: eclipse-wtp - In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XM...
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Scope: local
bookworm: resolved (fixed in 3.18-1)
bullseye: resolved (fixed in 3.18-1)
forky: resolved (fixed in 3.18-1)
sid: resolved (fixed in 3.18-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator [fedora-all]
bugzilla·2020-07-15·CVSS 7.1
CVE-2019-17637 [HIGH] CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator [fedora-all]
CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator
bugzilla·2020-07-15·CVSS 7.1
CVE-2019-17637 [HIGH] CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator
CVE-2019-17637 eclipse-webtools: XML external entity vulnerability in DTD Parser/Validator
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
Upstream bug:
https://bugs.eclipse.org/bugs/show_bug.cgi?id=458571
Discussion:
Created eclipse-webtools tracking bugs for this issue:
Affects: fedora-all [bug 1857370]
---
Patch:
https://git.eclipse.org/c/sourceediting/webtools.sourceediting.git/commit/?id=9644d4217cd6e3be367d654a8320104d88ddfd6b
2020-07-15
Published