296,213
Total vulnerabilities in the database
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
Software | From | Fixed in |
---|---|---|
eclipse / theia | 0.1.1 | 0.2.0.x |