Skip to content

[FP]: Incorrect CVE detection for CVE‑2023‑4218 #8173

@MohammedSuhaibT

Description

@MohammedSuhaibT

Package URl

pkg:maven/org.eclipse.angus/[email protected]

CPE

cpe:2.3:a:eclipse:eclipse_ide::::::::

CVE

CVE‑2023‑4218

ODC Integration

None

ODC Version

12.1.3

Description

Dependency Check flagged CVE‑2023‑4218, which affects Eclipse IDE (< 2023‑09 / 4.29) XML parsing:
Files with XML content may be vulnerable to XXE attacks if a user opens or updates a malicious project.
CWE‑611: Improper Restriction of XML External Entity Reference
CVSSv3 Base Score: 5.0 (Medium)

Analysis:
The Application does not use Eclipse IDE or its components.
Only secure versions of:
jaxb-core.jar (4.0.5)
angus-activation.jar (2.0.2)
are present.

Therefore, this alert is a false positive.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions