Candidate: CVE-2019-17637 PublicDate: 2020-07-15 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17637 https://bugs.eclipse.org/bugs/show_bug.cgi?id=458571 Description: In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N [7.1 HIGH] Patches_eclipse-wtp: upstream_eclipse-wtp: needs-triage precise/esm_eclipse-wtp: DNE trusty_eclipse-wtp: ignored (out of standard support) trusty/esm_eclipse-wtp: DNE xenial_eclipse-wtp: ignored (end of standard support, was needs-triage) bionic_eclipse-wtp: needs-triage eoan_eclipse-wtp: DNE focal_eclipse-wtp: DNE groovy_eclipse-wtp: not-affected (3.18-2) hirsute_eclipse-wtp: not-affected (3.18-2) impish_eclipse-wtp: not-affected (3.18-2) jammy_eclipse-wtp: not-affected (3.18-2) devel_eclipse-wtp: not-affected (3.18-2)