Known Vulnerabilities for Theia by Eclipse
Listed below are 7 of the newest known vulnerabilities associated with "Theia" by "Eclipse".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-41038 | In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMes... | 6.1 - MEDIUM | 2021-11-10 | 2021-11-13 |
| CVE-2021-34436 | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via th... | 9.8 - CRITICAL | 2021-09-02 | 2021-09-14 |
| CVE-2021-34435 | In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE... | 8.8 - HIGH | 2021-09-01 | 2022-10-27 |
| CVE-2021-28162 | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript c... | 6.1 - MEDIUM | 2021-03-12 | 2021-03-18 |
| CVE-2021-28161 | In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript ... | 6.1 - MEDIUM | 2021-03-12 | 2021-03-18 |
| CVE-2020-27224 | In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbit... | 9.6 - CRITICAL | 2021-02-24 | 2021-03-25 |
| CVE-2019-17636 | In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published... | 8.1 - HIGH | 2020-03-10 | 2020-03-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Eclipse | Theia | 0.9.0 | All | All | All |
| Application | Eclipse | Theia | 0.8.0 | All | All | All |
| Application | Eclipse | Theia | 0.7.2 | All | All | All |
| Application | Eclipse | Theia | 0.7.1 | All | All | All |
| Application | Eclipse | Theia | 0.7.0 | All | All | All |
| Application | Eclipse | Theia | 0.6.1 | All | All | All |
| Application | Eclipse | Theia | 0.6.0 | All | All | All |
| Application | Eclipse | Theia | 0.5.0 | All | All | All |
| Application | Eclipse | Theia | 0.4.0 | All | All | All |
| Application | Eclipse | Theia | 0.3.9 | All | All | All |
| Application | Eclipse | Theia | 0.3.8 | All | All | All |
| Application | Eclipse | Theia | 0.3.7 | All | All | All |
| Application | Eclipse | Theia | 0.3.6 | All | All | All |
| Application | Eclipse | Theia | 0.3.4 | All | All | All |
| Application | Eclipse | Theia | 0.3.3 | All | All | All |
| Application | Eclipse | Theia | 0.3.2 | All | All | All |
| Application | Eclipse | Theia | 0.3.19 | All | All | All |
| Application | Eclipse | Theia | 0.3.18 | All | All | All |
| Application | Eclipse | Theia | 0.3.17 | All | All | All |
| Application | Eclipse | Theia | 0.3.16 | All | All | All |