Vulnerability identifier: #VU26096
Vulnerability risk: High
CVSSv3.1: 7.1 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-345
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Eclipse Theia
Server applications /
Frameworks for developing and running applications
Vendor: Eclipse
Description
The vulnerability allows a remote attacker to read arbitrary files on the system.
The vulnerability exists due to the "Mini-Browser" extension exposes a HTTP endpoint. A remote attacker can perform a DNS rebinding attack or a drive-by download of a carefully crafted exploit and read the content of files on the host's filesystem, given their path, without restrictions on the requester's origin.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Eclipse Theia: 0.3.9 - 0.15.0
External links
http://bugs.eclipse.org/bugs/show_bug.cgi?id=551747
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.