Vulnerabilities > Eclipse > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-02-18 CVE-2022-0672 Information Exposure vulnerability in Eclipse Lemminx
A flaw was found in LemMinX in versions prior to 0.19.0.
local
low complexity
eclipse CWE-200
5.5
2022-02-18 CVE-2022-0673 Path Traversal vulnerability in Eclipse Lemminx
A flaw was found in LemMinX in versions prior to 0.19.0.
network
low complexity
eclipse CWE-22
6.5
2021-11-10 CVE-2021-41038 Unspecified vulnerability in Eclipse Theia
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
network
low complexity
eclipse
6.1
2021-08-30 CVE-2021-34434 Incorrect Authorization vulnerability in multiple products
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
network
low complexity
eclipse fedoraproject CWE-863
5.3
2021-07-22 CVE-2021-34431 Memory Leak vulnerability in Eclipse Mosquitto
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
network
low complexity
eclipse CWE-401
6.5
2021-07-15 CVE-2021-34429 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints.
network
low complexity
eclipse netapp oracle
5.3
2021-06-09 CVE-2021-28169 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory.
network
low complexity
eclipse debian oracle netapp
5.3
2021-06-02 CVE-2020-6950 Path Traversal vulnerability in multiple products
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
network
low complexity
eclipse oracle CWE-22
6.5
2021-05-26 CVE-2021-28170 Expression Language Injection vulnerability in multiple products
In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
network
low complexity
eclipse quarkus oracle CWE-917
5.3
2021-04-22 CVE-2021-28168 Exposure of Resource to Wrong Sphere vulnerability in multiple products
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability.
local
low complexity
eclipse oracle CWE-668
5.5