Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path stays within the plugin's directory. An unauthenticated network attacker can send percent-encoded `../` sequences (`%2e%2e%2f`) that decode into the path parameter and escape the plugin directory, allowing arbitrary files readable by the Theia backend process to be retrieved. Plugin IDs are derived deterministically from a plugin's publisher and name, so built-in plugins serve as reliable anchors that require no prior knowledge of the target system.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Eclipse Theia 路径遍历漏洞
Vulnerability Description
Eclipse Theia是美国Eclipse基金会开源的一个可构建云端及桌面集成开发环境的开发框架。 Eclipse Theia 1.66.0版本至1.73.1版本存在路径遍历漏洞,该漏洞源于@theia/plugin-ext后端在通过/hostedPlugin/:pluginId/:path(*)接口解析文件路径时未验证路径是否在插件目录内,未经身份验证的攻击者可通过发送百分号编码的`../`序列(`%2e%2e%2f`)逃离插件目录,导致读取后端进程可访问的任意文件。
CVSS Information
N/A
Vulnerability Type
N/A