Skip to content

[FP]: Wrongly reporting vulnerability CVE-2023-4218 on org.eclipse.core.expressions #7661

Open
@Subrhamanya

Description

@Subrhamanya

Package URl

pkg:maven/org.eclipse.core/[email protected]

CPE

cpe:2.3:a:eclipse:org.eclipse.core.runtime:3.4.300:370::::::

CVE

CVE-2023-4218

ODC Integration

{"label" => "Maven Plugin"}

ODC Version

10.0.3

Description

According to the discussion here, this CVE doesn't affect org.eclipse.core.expressions jar at all. (seems it's not affecting org.eclipse.platform:org.eclipse.osgi also even though it has some changes since it does no XML parsing)

To add more, it only affects Eclipse IDE rather than OSGI jar applications

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions