Description
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
Remediation
References
https://github.com/eclipse-theia/theia/issues/7283
Related Vulnerabilities
CVE-2023-29923 Vulnerability in maven package tech.powerjob:powerjob
CVE-2023-31581 Vulnerability in maven package com.usthe.sureness:sureness-core
CVE-2021-32827 Vulnerability in maven package org.mock-server:mockserver-core
CVE-2021-43138 Vulnerability in maven package org.webjars.npm:async
CVE-2022-36099 Vulnerability in maven package org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki