Vulnerabilities (CVE)

Filtered by vendor Eclipse Subscribe
Filtered by product Theia
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-34435 1 Eclipse 1 Theia 2021-09-10 6.8 MEDIUM 8.8 HIGH
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
CVE-2019-17636 1 Eclipse 1 Theia 2020-03-11 5.8 MEDIUM 8.1 HIGH
In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin. This design is vulnerable to being exploited remotely through a DNS rebinding attack or a drive-by download of a carefully crafted exploit.