7.8
CVE-2023-46944
- EPSS 1.24%
- Veröffentlicht 28.11.2023 22:15:06
- Zuletzt bearbeitet 21.11.2024 08:29:31
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.24% | 0.652 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
https://github.com/gitkraken/vscode-gitlens/commit/ee2a0c42a92d33059a39fd15fbbd5dd3d5ab6440
https://www.sonarsource.com/blog/vscode-security-markdown-vulnerabilities-in-extensions/