eclipse theia CVE-2019-17636 is a vulnerability in Eclipse Theia
Published on March 10, 2020

In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin. This design is vulnerable to being exploited remotely through a DNS rebinding attack or a drive-by download of a carefully crafted exploit.

NVD

Weakness Type

Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.


Products Associated with CVE-2019-17636

Want to know whenever a new CVE is published for Eclipse Theia? stack.watch will email you.

 

Affected Versions

The Eclipse Foundation Eclipse Theia Version 0.3.9 to 0.15.0 is affected by CVE-2019-17636

Exploit Probability

EPSS
0.12%
Percentile
30.80%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.