Client-Side Code Execution Vulnerability in GitLab VSCode Extension
CVE-2021-22195

8.6HIGH

Key Information:

Vendor
Gitlab
Vendor
CVE Published:
1 April 2021

Summary

A vulnerability exists in the GitLab VSCode Extension versions 3.15.0 and earlier that allows attackers to execute arbitrary code on the user's system. By exploiting this flaw, an attacker can leverage malicious payloads leading to unauthorized operations, potentially compromising user data and system integrity. Users are encouraged to update to the latest version to mitigate this risk and enhance their security posture.

Affected Version(s)

gitlab-vscode-extension <=3.15.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GitLab security research team
.