Vulnerabilities > Eclipse > Theia > 0.1.1

DATE CVE VULNERABILITY TITLE RISK
2021-11-10 CVE-2021-41038 Unspecified vulnerability in Eclipse Theia
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
network
eclipse
4.3
2021-09-02 CVE-2021-34436 XXE vulnerability in Eclipse Theia 0.1.1/0.2.0
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension.
network
low complexity
eclipse CWE-611
7.5
2021-03-12 CVE-2021-28162 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
network
eclipse CWE-829
4.3
2021-03-12 CVE-2021-28161 Cross-site Scripting vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
network
eclipse CWE-79
4.3
2021-02-24 CVE-2020-27224 Cross-site Scripting vulnerability in Eclipse Theia
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
network
eclipse CWE-79
critical
9.3