PT-2021-14490 · Prisma · Prisma Vs Code

Ryotak

·

Published

2021-04-29

·

Updated

2022-10-21

·

CVE-2021-21415

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Prisma VS Code versions prior to 2.20.0
Description This issue is a Remote Code Execution vulnerability. It affects the Prisma VS Code extension when a custom binary path for the Prisma format binary is set in VS Code Settings, for example, through a .vscode/settings.json file that sets a value for prismaFmtBinPath. The custom binary is executed during auto-formatting or validation checks on *.prisma files.
Recommendations For versions prior to 2.20.0, as a temporary workaround, users can edit or delete the .vscode/settings.json file, or check if the binary is malicious and delete it. To fully resolve the issue, update to version 2.20.0 or later.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21415
GHSA-4RF9-43M7-X828

Affected Products

Prisma Vs Code