CVE-2020-13279: High severity gitlab vscode extension vulnerability
Published Jun 22, 2020
·Updated
Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system
Affected Software
1 affected component
GitLab gitlab-vscode-extension<=2.2.0
Event History
Jun 22, 2020
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-13279?
CVE-2020-13279 is considered a critical vulnerability due to its potential for arbitrary code execution on user systems.
2
How do I fix CVE-2020-13279?
To fix CVE-2020-13279, users should upgrade to a version of the gitlab-vscode-extension that is above 2.2.0 or apply any available patches.
3
What can an attacker do with CVE-2020-13279?
An attacker exploiting CVE-2020-13279 can execute arbitrary code on the victim's machine, compromising the security of the system.
4
Which versions of gitlab-vscode-extension are affected by CVE-2020-13279?
CVE-2020-13279 affects all versions of gitlab-vscode-extension up to and including 2.2.0.
5
Is there a workaround for CVE-2020-13279?
There's no specific workaround for CVE-2020-13279; the recommended action is to update to a secure version of the extension.