CVE-2020-27224: XSS
Published Feb 24, 2021
·Updated
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
Affected Software
1 affected component
Eclipse theia<=1.2.0
Event History
Feb 24, 2021
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-27224?
CVE-2020-27224 is a vulnerability in Eclipse Theia versions up to and including 1.2.0 that allows for the execution of arbitrary code through the Markdown Preview component.
2
How severe is CVE-2020-27224?
CVE-2020-27224 is classified as critical with a severity rating of 9.6 out of 10.
3
What software versions are affected by CVE-2020-27224?
Eclipse Theia versions up to and including 1.2.0 are affected by CVE-2020-27224.
4
How can CVE-2020-27224 be exploited?
CVE-2020-27224 can be exploited by leveraging the Markdown Preview (@theia/preview) component in Eclipse Theia.
5
Is there a fix available for CVE-2020-27224?
There is currently no fix available for CVE-2020-27224. It is recommended to apply any patches or updates provided by the vendor.