eclipse theia CVE-2021-34436 is a vulnerability in Eclipse Theia
Published on September 2, 2021

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.

NVD

Weakness Types

What is a XXE Vulnerability?

The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

CVE-2021-34436 has been classified to as a XXE vulnerability or weakness.

What is a Directory traversal Vulnerability?

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CVE-2021-34436 has been classified to as a Directory traversal vulnerability or weakness.


Products Associated with CVE-2021-34436

Want to know whenever a new CVE is published for Eclipse Theia? stack.watch will email you.

 

Affected Versions

The Eclipse Foundation Eclipse Theia:

Exploit Probability

EPSS
3.50%
Percentile
87.44%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.