Description
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
Remediation
References
https://bugs.eclipse.org/bugs/show_bug.cgi?id=568018
Related Vulnerabilities
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-jms-processors
CVE-2022-44310 Vulnerability in npm package ecdh
CVE-2021-23448 Vulnerability in npm package config-handler
CVE-2020-35491 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-50730 Vulnerability in maven package edu.gemini:gsp-graphql-core_sjs1_3