QID 980121
QID 980121: Nodejs (npm) Security Update for @theia/plugin-ext (GHSA-w6v7-w58j-pg5r)
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w6v7-w58j-pg5r for updates pertaining to this vulnerability.
Vendor References
- GHSA-w6v7-w58j-pg5r -
github.com/advisories/GHSA-w6v7-w58j-pg5r
CVEs related to QID 980121
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w6v7-w58j-pg5r | @theia/plugin-ext |
|