In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences.
| Software | From | Fixed in |
|---|---|---|
| eclipse / web_tools_platform | 1.0 | 3.18.x |
| debian / debian_linux | 9.0 | 9.0.x |