Vulnerabilities > Eclipse > Theia > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-01 CVE-2021-34435 Origin Validation Error vulnerability in Eclipse Theia
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE.
network
low complexity
eclipse CWE-346
8.8
2020-03-10 CVE-2019-17636 Insufficient Verification of Data Authenticity vulnerability in Eclipse Theia
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com.
network
low complexity
eclipse CWE-345
8.1