CVE Database
/

CVE-2021-34436

Back to search

CVE-2021-34436

Published: Sep 2, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

VendorProductVersions

The Eclipse Foundation

Eclipse Theia

affected
0.1.1
affected
0.1.2
affected
0.2.0-next.28bc2735
affected
0.2.0-next.41406d98
affected
0.2.0-next.a2958907

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now