HIGH

CVE-2021-22195

Gitlab Gitlab Vscode Extension 2021-04-01 CVSS v3.1
CVSS
7.8

Description

Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system

Summary dbcve.org

The GitLab VSCode extension before version 3.15.0 contains a client-side code execution vulnerability. An attacker could potentially craft malicious content (such as issues, merge requests, or other GitLab resources) that, when opened by a user with the vulnerable extension installed, would allow arbitrary code execution on the user's local system.

Mitigation

Upgrade the GitLab VSCode extension to a version newer than 3.15.0. Users should update immediately as this vulnerability can be triggered simply by opening malicious GitLab content.

Weakness (CWE)

CWE-427 Uncontrolled Search Path (DLL Hijack)

EPSS Score

1.14%
Probability of exploitation in next 30 days
65.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE