PT-2022-13346 · Lemminx · Lemminx

Published

2022-02-18

·

Updated

2022-02-26

·

CVE-2022-0672

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LemMinX versions prior to 0.19.0
Description A flaw in LemMinX allows for insecure redirect, which could enable unauthorized access to sensitive information locally if LemMinX is run under a privileged user.
Recommendations For versions prior to 0.19.0, update to version 0.19.0 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0672
GHSA-HRXV-694F-22G3

Affected Products

Lemminx