← Back

Xml Server Project

xml_server_project

Vendor: Xml Language Server Project • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Eclipse
Theia Xml Extension ProjectXml Language Server Project
3Theia Xml Extension
Wild Web DeveloperXml Server Project
Nov 21, 2024
Oct 23, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as w...Show more
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows XXE via a crafted XML document, with resultant SSRF (as well as SMB connection initiation that can lead to NetNTLM challenge/response capture for password cracking). This occurs in extensions/contentmodel/participants/diagnostics/LSPXMLParserConfiguration.java.Show less
3Eclipse
Theia Xml Extension ProjectXml Language Server Project
3Theia Xml Extension
Wild Web DeveloperXml Server Project
Nov 21, 2024
Oct 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to...Show more
XMLLanguageService.java in XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other products, allows a remote attacker to write to arbitrary files via Directory Traversal.Show less