PT-2021-14490 · Prisma · Prisma Vs Code
Ryotak
·
Published
2021-04-29
·
Updated
2022-10-21
·
CVE-2021-21415
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Prisma VS Code versions prior to 2.20.0
Description
This issue is a Remote Code Execution vulnerability. It affects the Prisma VS Code extension when a custom binary path for the Prisma format binary is set in VS Code Settings, for example, through a
.vscode/settings.json file that sets a value for prismaFmtBinPath. The custom binary is executed during auto-formatting or validation checks on *.prisma files.Recommendations
For versions prior to 2.20.0, as a temporary workaround, users can edit or delete the
.vscode/settings.json file, or check if the binary is malicious and delete it. To fully resolve the issue, update to version 2.20.0 or later.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prisma Vs Code