Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-4218

19
FAUCET Score

CVE-2023-4218 is a Medium severity XML External Entity (XXE) vulnerability affecting Eclipse IDE versions prior to 2023-09 (4.29), as well as eclipse.org.eclipse.core.runtime and eclipse pde. An attacker can exploit this by enticing a user to open a malicious project or update an existing project containing a vulnerable XML file, leading to potential disclosure of sensitive information. The CVSS score is 5.0 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N), indicating a local attack with user interaction required, but high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.29CPE matchmatch criteria
cpe:2.3:a:eclipse:eclipse_ide:*:*:*:*:*:*:*:*
< 3.29.0CPE matchmatch criteria
cpe:2.3:a:eclipse:org.eclipse.core.runtime:*:*:*:*:*:*:*:*
< 3.13.2400CPE matchmatch criteria
cpe:2.3:a:eclipse:pde:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.3
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 68th percentile among its peer group of 381 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.core.runtimeFixed in: 3.29.0
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.platformFixed in: 4.29.0
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.jfaceFixed in: 3.31.0
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.ui.formsFixed in: 3.13.0
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.ui.ideFixed in: 3.21.100
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.ui.workbenchFixed in: 3.130.0
mavenpatch availablevia ghsa
Product: org.eclipse.platform:org.eclipse.urischemeFixed in: 1.3.100
mavenpatch availablevia ghsa
Product: org.eclipse.jdt:org.eclipse.jdt.uiFixed in: 3.30.0

Vendor Advisories (1)

mavenGHSA-j24h-xcpc-9jw8medium

Eclipse IDE XXE in eclipse.platform

Nov 30, 2023

References

github.com / eclipse-cdt/cdt/commit/c7169b3186d2fef20f97467c3e2ad78e2943ed1b
Patch
github.com / eclipse-emf/org.eclipse.emf/issues/10
Issue TrackingThird Party Advisory
github.com / eclipse-jdt/eclipse.jdt.core/commit/38dd2a878f45cdb3d8d52090f1d6d1b532fd4c4d
Patch
github.com / eclipse-jdt/eclipse.jdt.ui/commit/13675b1f8a74f47de4da89ed0ded6af7c21dfbec
Patch
github.com / eclipse-pde/eclipse.pde/pull/632
Patch
github.com / eclipse-pde/eclipse.pde/pull/667
Patch
github.com / eclipse-platform/eclipse.platform/pull/761
Patch
github.com / eclipse-platform/eclipse.platform.releng.buildtools/pull/45
Patch
github.com / eclipse-platform/eclipse.platform.swt/commit/bf71db5ddcb967c0863dad4745367b54f49e06ba
Patch
github.com / eclipse-platform/eclipse.platform.ui/commit/f243cf0a28785b89b7c50bf4e1cce48a917d89bd
Patch
gitlab.eclipse.org / security/vulnerability-reports/-/issues/8
ExploitIssue TrackingVendor Advisory