Description
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
Remediation
References
https://github.com/eclipse/lemminx/blob/master/CHANGELOG.md#0190-february-14-2022
Related Vulnerabilities
CVE-2019-10293 Vulnerability in maven package org.jenkins-ci.plugins:kmap-jenkins
CVE-2022-1330 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2018-15494 Vulnerability in maven package org.webjars.npm:dojox
CVE-2021-4264 Vulnerability in maven package org.webjars.bower:dustjs-linkedin
CVE-2018-1000615 Vulnerability in maven package org.onosproject:onos-ovsdb