CVE-2021-28472: Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
Published Apr 13, 2021
·Updated
Visual Studio Code Maven for Java Extension Remote Code Execution Vulnerability
Affected Software
1 affected component
Microsoft Vscode-maven<0.29.0
Remediation
Event History
Apr 13, 2021
CVE Published
07:33 PM
Data Sourced
07:33 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-28472?
CVE-2021-28472 is rated as high severity due to its potential for remote code execution.
2
How do I fix CVE-2021-28472?
To mitigate CVE-2021-28472, update the Visual Studio Code Maven for Java Extension to version 0.29.0 or later.
3
What vulnerability does CVE-2021-28472 exploit?
CVE-2021-28472 exploits a remote code execution vulnerability within the Visual Studio Code Maven for Java Extension.
4
Who is affected by CVE-2021-28472?
Users of the Visual Studio Code Maven for Java Extension prior to version 0.29.0 are affected by CVE-2021-28472.
5
Is there a workaround for CVE-2021-28472 if I cannot update?
Currently, there are no known workarounds for CVE-2021-28472; updating the extension is the recommended action.