Client-Side Code Execution Vulnerability in GitLab VSCode Extension
CVE-2021-22195
8.6HIGH
Summary
A vulnerability exists in the GitLab VSCode Extension versions 3.15.0 and earlier that allows attackers to execute arbitrary code on the user's system. By exploiting this flaw, an attacker can leverage malicious payloads leading to unauthorized operations, potentially compromising user data and system integrity. Users are encouraged to update to the latest version to mitigate this risk and enhance their security posture.
Affected Version(s)
gitlab-vscode-extension <=3.15.0
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
GitLab security research team