Vulnerabilities
Vulnerable Software
Eclipse:  >> Theia  >> 1.8.1  Security Vulnerabilities
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
CVSS Score
6.1
EPSS Score
0.003
Published
2021-11-10
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
CVSS Score
8.8
EPSS Score
0.002
Published
2021-09-01


Contact Us

Shodan ® - All rights reserved