Visual Studio Code Jupyter Extension Spoofing Vulnerability
CVE-2023-36018

7.8HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 November 2023

Summary

The Visual Studio Code Jupyter Extension is susceptible to a spoofing vulnerability, allowing attackers to potentially manipulate the user interface. This can mislead users into believing they are interacting with legitimate content or prompts, leading to potential unauthorized actions. It is crucial for users of this extension to remain vigilant and stay updated with the latest security practices and patches provided by Microsoft to mitigate any risks associated with this issue.

Affected Version(s)

Jupyter Extension for Visual Studio Code Unknown 2022.0.0 < 2023.10.1100000000

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.