CVE-2021-34436
02.09.2021, 21:15
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
Vendor | Product | Version |
---|---|---|
eclipse | theia | 0.1.1 ≤ 𝑥 ≤ 0.2.0 |
𝑥
= Vulnerable software versions