Description
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
Remediation
References
https://github.com/eclipse/lemminx/blob/master/CHANGELOG.md#0190-february-14-2022
Related Vulnerabilities
CVE-2021-21412 Vulnerability in npm package @thi.ng/egf
CVE-2019-1003057 Vulnerability in maven package org.jenkins-ci.plugins:bitbucket-approve
CVE-2021-23597 Vulnerability in npm package fastify-multipart
CVE-2018-25031 Vulnerability in maven package org.webjars.npm:swagger-ui-dist
CVE-2018-8028 Vulnerability in maven package org.apache.sentry:sentry-binding-hive