Lucene search

K
cvelistEclipseCVELIST:CVE-2021-34436
HistorySep 02, 2021 - 8:55 p.m.

CVE-2021-34436

2021-09-0220:55:10
CWE-22
CWE-611
eclipse
www.cve.org
6
cve-2021-34436
eclipse theia
remote code execution
xml extension
lsp4xml
lemminx

AI Score

9.9

Confidence

High

EPSS

0.005

Percentile

76.8%

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

CNA Affected

[
  {
    "product": "Eclipse Theia",
    "vendor": "The Eclipse Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "0.1.1"
      },
      {
        "status": "affected",
        "version": "0.1.2"
      },
      {
        "status": "affected",
        "version": "0.2.0-next.28bc2735"
      },
      {
        "status": "affected",
        "version": "0.2.0-next.41406d98"
      },
      {
        "status": "affected",
        "version": "0.2.0-next.a2958907"
      }
    ]
  }
]

AI Score

9.9

Confidence

High

EPSS

0.005

Percentile

76.8%

Related for CVELIST:CVE-2021-34436