First published: Fri Feb 18 2022(Updated: )
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Lemminx | <0.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2022-0672.
The severity of CVE-2022-0672 is medium (CVSS score: 5.5).
LemMinX versions prior to 0.19.0 are affected by CVE-2022-0672.
Unauthorized access to sensitive information locally can be gained if LemMinX is run under a privileged user.
Yes, upgrading to LemMinX version 0.19.0 or higher will fix the vulnerability.