First published: Thu Apr 01 2021(Updated: )
vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. The update addresses the vulnerability by modifying the way the extension validates its settings.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Stripe | <1.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21420 has a high severity rating due to the possibility of arbitrary code execution.
To fix CVE-2021-21420, update the Stripe extension for Visual Studio Code to version 1.7.3 or later.
CVE-2021-21420 affects all versions of the Stripe extension for Visual Studio Code up to version 1.7.3.
By exploiting CVE-2021-21420, an attacker can run arbitrary code on the user's machine.
As a temporary workaround for CVE-2021-21420, avoid loading untrusted source code repositories while using the Stripe extension.