CVE-2021-41038: Medium severity eclipse theia vulnerability
Published Nov 10, 2021
·Updated
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Affected Software
1 affected component
Eclipse theia<1.18.0
Remediation
Patch Available
Event History
Nov 10, 2021
CVE Published
via MITRE·05:05 PM
Data Sourced
via MITRE·05:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-41038.
2
What is the title of this vulnerability?
The title of this vulnerability is 'In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0 Webview contents can…'
3
What is the description of this vulnerability?
The description of this vulnerability is 'In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().'
4
What is the severity of CVE-2021-41038?
The severity of CVE-2021-41038 is medium.
5
How do I fix CVE-2021-41038?
To fix CVE-2021-41038, update the @theia/plugin-ext component of Eclipse Theia to version 1.18.0 or later.