org.eclipse.lemminx:lemminx-parent
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.eclipse.lemminx:lemminx-parentpage 1 of 1
- CVE-2022-0671CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.19.02022-02-18
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
- CVE-2022-0672MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.19.02022-02-18
A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
- CVE-2022-0673MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.19.02022-02-18
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.
Check whether org.eclipse.lemminx:lemminx-parent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.eclipse.lemminx:lemminx-parent CVEs against the assets you own.
Start Free Scan →