Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8gpx-73gc-wq7c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

EPSS

Процентиль: 87%
0.035
Низкий

Дефекты

CWE-22
CWE-611

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

EPSS

Процентиль: 87%
0.035
Низкий

Дефекты

CWE-22
CWE-611