CVE Database
/

CVE-2021-41038

Back to search

CVE-2021-41038

Published: Nov 10, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

VendorProductVersions

The Eclipse Foundation

@theia/plugin-ext

affected
unspecified - < 1.18.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now