PT-2021-14493 · Unknown · Vscode-Stripe

David Dworken

·

Published

2021-04-01

·

Updated

2022-08-12

·

CVE-2021-21420

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vscode-stripe (affected versions not specified)
Description A vulnerability exists in the Stripe for Visual Studio Code extension when it loads an untrusted source-code repository containing malicious settings. This could allow an attacker to run arbitrary code in the context of the current user. The issue is related to the extension's validation of its settings.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-21420
GHSA-J6X4-4622-8VV3

Affected Products

Vscode-Stripe