Description
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2115 | In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file.. |
Github GHSA |
GHSA-v9w2-v7j9-rjpr | Remote code execution in Eclipse Theia |
References
| Link | Providers |
|---|---|
| https://bugs.eclipse.org/bugs/show_bug.cgi?id=568018 |
|
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-04T00:12:50.149Z
Reserved: 2021-06-09T00:00:00.000Z
Link: CVE-2021-34435
No data.
Status : Modified
Published: 2021-09-01T18:15:09.107
Modified: 2024-11-21T06:10:24.447
Link: CVE-2021-34435
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA