First published: Fri Feb 18 2022(Updated: )
A flaw was found in vscode-xml in versions prior to 0.19.0. Schema download could lead to blind SSRF or DoS via a large file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Vscode-xml | <0.19.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0671 is a vulnerability found in vscode-xml versions prior to 0.19.0 that can lead to blind SSRF or DoS through schema download.
CVE-2022-0671 has a severity rating of 9.1 (critical).
Red Hat vscode-xml versions prior to 0.19.0 are affected by CVE-2022-0671.
To fix CVE-2022-0671, update vscode-xml to version 0.19.0 or later.
You can find more information about CVE-2022-0671 in the following references: - [CVE-2022-0671 on GitHub - eclipse/lemminx](https://github.com/eclipse/lemminx/blob/master/CHANGELOG.md#0190-february-14-2022) - [CVE-2022-0671 on GitHub - redhat-developer/vscode-xml](https://github.com/redhat-developer/vscode-xml/blob/master/CHANGELOG.md#0190-february-14-2022)