First published: Wed Nov 10 2021(Updated: )
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Theia | <1.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-41038.
The title of this vulnerability is 'In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0 Webview contents can…'
The description of this vulnerability is 'In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().'
The severity of CVE-2021-41038 is medium.
To fix CVE-2021-41038, update the @theia/plugin-ext component of Eclipse Theia to version 1.18.0 or later.