QID 982788
QID 982788: Nodejs (npm) Security Update for @theia/console (GHSA-cwg9-c9cr-p5fq)
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cwg9-c9cr-p5fq for updates pertaining to this vulnerability.
Vendor References
- GHSA-cwg9-c9cr-p5fq -
github.com/advisories/GHSA-cwg9-c9cr-p5fq
CVEs related to QID 982788
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cwg9-c9cr-p5fq | @theia/console |
|