First published: Mon Jun 22 2020(Updated: )
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab VSCode Extension | <=2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13279 is considered a critical vulnerability due to its potential for arbitrary code execution on user systems.
To fix CVE-2020-13279, users should upgrade to a version of the gitlab-vscode-extension that is above 2.2.0 or apply any available patches.
An attacker exploiting CVE-2020-13279 can execute arbitrary code on the victim's machine, compromising the security of the system.
CVE-2020-13279 affects all versions of gitlab-vscode-extension up to and including 2.2.0.
There's no specific workaround for CVE-2020-13279; the recommended action is to update to a secure version of the extension.