CVE-2021-28161: XSS
Published Mar 12, 2021
·Updated
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
Affected Software
1 affected component
Eclipse theia<=1.8.0
Event History
Mar 12, 2021
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this Eclipse Theia vulnerability?
The vulnerability ID of this Eclipse Theia vulnerability is CVE-2021-28161.
2
What is the severity of CVE-2021-28161?
The severity of CVE-2021-28161 is medium with a CVSS score of 6.1.
3
In which versions of Eclipse Theia is this vulnerability present?
This vulnerability is present in Eclipse Theia versions up to and including 1.8.0.
4
What is the impact of CVE-2021-28161?
The impact of CVE-2021-28161 is that arbitrary JavaScript code can be injected in the debug console.
5
Is there a fix available for CVE-2021-28161?
Yes, a fix is available for CVE-2021-28161. It is recommended to update to a version beyond 1.8.0.