Browse all 95 CVE security advisories affecting Eclipse Foundation. AI-powered Chinese analysis, POCs, and references for each vulnerability.
The Eclipse Foundation operates as a non-profit organization managing an open-source ecosystem, primarily hosting the Eclipse Integrated Development Environment (IDE) and related tooling. Its infrastructure supports a vast array of plugins and projects, creating a complex attack surface that has historically resulted in numerous security vulnerabilities. Recorded Common Vulnerabilities and Exposures (CVEs) frequently involve remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from input validation errors or insecure default configurations within specific plugins rather than the core platform itself. While the Foundation maintains rigorous governance and security advisory processes, the decentralized nature of its project portfolio means individual components may lag in patching. Notable incidents have highlighted risks associated with supply chain dependencies and outdated libraries within the broader ecosystem. Consequently, users must prioritize regular updates and strict plugin vetting to mitigate exposure to these historically common vulnerability classes.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-4760 | Remote Code Execution in Eclipse RAP on Windows — Eclipse RAPCWE-22 | 7.6 | High | 2023-09-21 |
| CVE-2023-4759 | Improper handling of case insensitive filesystems in Eclipse JGit allows arbitrary file write — Eclipse JGitCWE-59 | 8.8 | High | 2023-09-12 |
| CVE-2023-2597 | Eclipse OpenJ9 缓冲区错误漏洞 — Eclipse OpenJ9CWE-120 | 7.0 | High | 2023-05-22 |
| CVE-2017-7650 | Eclipse Mosquitto 安全漏洞 — Mosquitto | 6.5 | - | 2017-09-11 |
| CVE-2017-7649 | Eclipse Kura 安全漏洞 — Eclipse Kura Installer | 8.1 | - | 2017-09-11 |
This page lists every published CVE security advisory associated with Eclipse Foundation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.