CVE-2021-28162: Medium severity eclipse theia vulnerability
Published Mar 12, 2021
·Updated
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
Affected Software
1 affected component
Eclipse theia<=0.16.0
Event History
Mar 12, 2021
CVE Published
via MITRE·09:40 PM
Data Sourced
via MITRE·09:40 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-28162?
CVE-2021-28162 is a vulnerability in Eclipse Theia versions up to and including 0.16.0 that allows Javascript code to run through the lack of HTML escaping in notification messages.
2
How severe is CVE-2021-28162?
CVE-2021-28162 has a severity rating of 6.1, which is considered medium.
3
What software versions are affected by CVE-2021-28162?
Eclipse Theia versions up to and including 0.16.0 are affected by CVE-2021-28162.
4
How can I fix CVE-2021-28162?
To fix CVE-2021-28162, it is recommended to upgrade to a version of Eclipse Theia that is greater than 0.16.0.
5
Where can I find more information about CVE-2021-28162?
You can find more information about CVE-2021-28162 on the official GitHub page for Eclipse Theia: https://github.com/eclipse-theia/theia/issues/7283.