6.1
CVE-2019-1486
- EPSS 0.29%
- Published 10.12.2019 22:15:18
- Last modified 21.11.2024 04:36:46
- Source secure@microsoft.com
- Teams watchlist Login
- Open Login
A spoofing vulnerability exists in Visual Studio Live Share when a guest connected to a Live Share session is redirected to an arbitrary URL specified by the session host, aka 'Visual Studio Live Share Spoofing Vulnerability'.
Data is provided by the National Vulnerability Database (NVD)
Microsoft ≫ Visual Studio 2019 Version >= 16.0 <= 16.4
Microsoft ≫ Visual Studio Live Share SwPlatformvisual_studio Version < 1.0.1374
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.29% | 0.496 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.