Vulnerabilities > Eclipse > Theia

DATE CVE VULNERABILITY TITLE RISK
2021-11-10 CVE-2021-41038 Unspecified vulnerability in Eclipse Theia
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
network
low complexity
eclipse
6.1
2021-09-02 CVE-2021-34436 XXE vulnerability in Eclipse Theia 0.1.1/0.2.0
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension.
network
low complexity
eclipse CWE-611
critical
9.8
2021-09-01 CVE-2021-34435 Origin Validation Error vulnerability in Eclipse Theia
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.
network
low complexity
eclipse CWE-346
8.8
2021-03-12 CVE-2021-28162 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
network
low complexity
eclipse CWE-829
6.1
2021-03-12 CVE-2021-28161 Cross-site Scripting vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
network
low complexity
eclipse CWE-79
6.1
2021-02-24 CVE-2020-27224 Cross-site Scripting vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
network
low complexity
eclipse CWE-79
critical
9.6
2020-03-10 CVE-2019-17636 Insufficient Verification of Data Authenticity vulnerability in Eclipse Theia
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com.
network
low complexity
eclipse CWE-345
8.1