QID 982629
QID 982629: Nodejs (npm) Security Update for @theia/messages (GHSA-c94v-8fff-73ph)
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c94v-8fff-73ph for updates pertaining to this vulnerability.
Vendor References
- GHSA-c94v-8fff-73ph -
github.com/advisories/GHSA-c94v-8fff-73ph
CVEs related to QID 982629
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c94v-8fff-73ph | @theia/messages |
|