QID 980121

QID 980121: Nodejs (npm) Security Update for @theia/plugin-ext (GHSA-w6v7-w58j-pg5r)

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-w6v7-w58j-pg5r for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980121

    Software Advisories
    Advisory ID Software Component Link
    GHSA-w6v7-w58j-pg5r @theia/plugin-ext URL Logo github.com/advisories/GHSA-w6v7-w58j-pg5r