Vulnerabilities/

Improper Verification of Communication Channel in @theia/plugin-ext

Severity:
Medium

Description

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

Recommendation

Update the @theia/plugin-ext package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@theia/plugin-ext
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing