Логотип exploitDog
bind:CVE-2019-17636
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-17636

Количество 2

Количество 2

nvd логотип

CVE-2019-17636

почти 6 лет назад

In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin. This design is vulnerable to being exploited remotely through a DNS rebinding attack or a drive-by download of a carefully crafted exploit.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-f7vx-j8mp-3h2x

почти 5 лет назад

Insufficient Verification of Data Authenticity in Eclipse Theia

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-17636

In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin. This design is vulnerable to being exploited remotely through a DNS rebinding attack or a drive-by download of a carefully crafted exploit.

CVSS3: 8.1
0%
Низкий
почти 6 лет назад
github логотип
GHSA-f7vx-j8mp-3h2x

Insufficient Verification of Data Authenticity in Eclipse Theia

CVSS3: 8.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу