Eclipse Foundation Eclipse Open VSX是Eclipse Foundation基金会的一款扩展市场平台。 Eclipse Foundation Eclipse Open VSX 1.0.2之前版本存在跨站脚本漏洞,该漏洞源于端点服务于用户提供的HTML文件,未设置Content-Security-Policy或Content-Disposition响应头,可能导致攻击者注册发布者账户、上传含特制HTML有效载荷的VSIX,诱导用户访问URL后导致会话令牌泄露、持久性个人访问令
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Open VSX | 0.1.0< 1.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Open VSX | 0.1.0 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet