CVE-2023-4218 is a Medium severity XML External Entity (XXE) vulnerability affecting Eclipse IDE versions prior to 2023-09 (4.29), as well as eclipse.org.eclipse.core.runtime and eclipse pde. An attacker can exploit this by enticing a user to open a malicious project or update an existing project containing a vulnerable XML file, leading to potential disclosure of sensitive information. The CVSS score is 5.0 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N), indicating a local attack with user interaction required, but high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.29CPE matchmatch criteria | cpe:2.3:a:eclipse:eclipse_ide:*:*:*:*:*:*:*:* | ||
< 3.29.0CPE matchmatch criteria | cpe:2.3:a:eclipse:org.eclipse.core.runtime:*:*:*:*:*:*:*:* | ||
< 3.13.2400CPE matchmatch criteria | cpe:2.3:a:eclipse:pde:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.