Insecure File Exposure in Eclipse Theia Mini-Browser Extension
CVE-2019-17636
8.1HIGH
What is CVE-2019-17636?
The Eclipse Theia Mini-Browser extension exposes a HTTP endpoint that inadvertently allows unauthorized access to the host's filesystem. This vulnerability permits remote attackers to exploit the system via DNS rebinding or drive-by downloads, better enabling access to sensitive files provided the attacker knows the file paths. It underscores the necessity for stricter validation mechanisms to prevent unauthorized file accessibility.
Affected Version(s)
Eclipse Theia 0.3.9 to 0.15.0