eclipse theia CVE-2021-34435 is a vulnerability in Eclipse Theia
Published on September 1, 2021

In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..

NVD

Weakness Type

Permissive Cross-domain Policy with Untrusted Domains

The software uses a cross-domain policy file that includes domains that should not be trusted.


Products Associated with CVE-2021-34435

Want to know whenever a new CVE is published for Eclipse Theia? stack.watch will email you.

 

Affected Versions

The Eclipse Foundation Eclipse Theia:

Exploit Probability

EPSS
0.12%
Percentile
31.27%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.