CVE-2022-0673: Path Traversal
Published Feb 18, 2022
·Updated
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
Affected Software
1 affected component
Eclipse Lemminx<0.19.0
Event History
Feb 18, 2022
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this flaw in LemMinX?
The vulnerability ID is CVE-2022-0673.
2
What is the severity of CVE-2022-0673?
The severity of CVE-2022-0673 is medium (6.5).
3
What is the affected software for CVE-2022-0673?
The affected software for CVE-2022-0673 is Eclipse LemMinX versions prior to 0.19.0.
4
What is the impact of this vulnerability?
The vulnerability in LemMinX allows cache poisoning of external schema files due to directory traversal.
5
How do I fix CVE-2022-0673?
To fix CVE-2022-0673, upgrade to LemMinX version 0.19.0 or later.