CVE-2021-22195: Command Injection
Published Apr 1, 2021
·Updated
Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
Affected Software
1 affected component
GitLab gitlab-vscode-extension<=3.15.0
Event History
Apr 1, 2021
CVE Published
via MITRE·05:36 PM
Data Sourced
via MITRE·05:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22195?
CVE-2021-22195 has a high severity rating due to its potential for client-side code execution.
2
How do I fix CVE-2021-22195?
To fix CVE-2021-22195, update the GitLab VSCode Extension to a version later than 3.15.0.
3
What systems are affected by CVE-2021-22195?
CVE-2021-22195 affects users of the GitLab VSCode Extension versions 3.15.0 and earlier.
4
What is the impact of CVE-2021-22195?
The impact of CVE-2021-22195 allows an attacker to execute arbitrary code on the user's system.
5
Is CVE-2021-22195 remotely exploitable?
CVE-2021-22195 is not remotely exploitable as it requires user interaction to trigger the vulnerability.