← Back to CVE List

CVE-2023-6194

Published: 2023-12-11T14:15Z
Last Modified: 2024-11-21T08:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entity reference to generate a report then Eclipse Memory Analyzer may access external files or URLs defined via a DTD in the report definition. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt