First published: Fri Mar 12 2021(Updated: )
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Theia | <=0.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28162 is a vulnerability in Eclipse Theia versions up to and including 0.16.0 that allows Javascript code to run through the lack of HTML escaping in notification messages.
CVE-2021-28162 has a severity rating of 6.1, which is considered medium.
Eclipse Theia versions up to and including 0.16.0 are affected by CVE-2021-28162.
To fix CVE-2021-28162, it is recommended to upgrade to a version of Eclipse Theia that is greater than 0.16.0.
You can find more information about CVE-2021-28162 on the official GitHub page for Eclipse Theia: https://github.com/eclipse-theia/theia/issues/7283.