First published: Thu Sep 02 2021(Updated: )
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Theia | >=0.1.1<=0.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34436 is a vulnerability in Eclipse Theia 0.1.1 to 0.2.0 that allows an attacker to exploit the default build and obtain remote code execution and XXE (XML External Entity) through the theia-xml-extension.
This vulnerability can be exploited by leveraging the default build in Eclipse Theia 0.1.1 to 0.2.0 via the theia-xml-extension, which uses lsp4xml (LemMinX) to provide XML language support.
CVE-2021-34436 has a severity rating of critical with a CVSS score of 9.8.
Eclipse Theia versions 0.1.1 to 0.2.0 are affected by CVE-2021-34436.
To fix this vulnerability, it is recommended to upgrade Eclipse Theia to a version beyond 0.2.0.