HIGH

CVE-2020-13279

Gitlab Gitlab Vscode Extension 2020-06-22 CVSS v3.1
CVSS
8.6

Description

Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system

Summary dbcve.org

Client-side code execution vulnerability in the GitLab VSCode Extension v2.2.0 allows an attacker to execute arbitrary code on a user's local system through the extension, likely via malicious content processed from GitLab repositories or communications.

Mitigation

Update the GitLab VSCode Extension to the latest patched version and audit systems for the vulnerable version.

Weakness (CWE)

CWE-427 Uncontrolled Search Path (DLL Hijack)

EPSS Score

1.2%
Probability of exploitation in next 30 days
66.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE