Eclipse Foundation Eclipse Open VSX是Eclipse Foundation基金会的一款扩展市场平台。 Eclipse Foundation Eclipse Open VSX存在跨站脚本漏洞,该漏洞源于未在存储前清理上传为扩展图标的SVG文件,并且以Content-Type: image/svg+xml提供而无安全标头,可能导致攻击者发布带恶意SVG图标的扩展,用户直接导航至图标URL时实现存储型跨站脚本,从而引发会话劫持、身份验证令牌窃取和未授权扩展发布;对于外部存储部署
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse Open VSX | 0.1.0< 0.34.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Eclipse Foundation | Eclipse Open VSX | 0.1.0 ~ 0.34.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet