PT-2023-9085 · Microsoft+1 · Visual Studio Code+1

Paul Gerste

·

Published

2023-06-07

·

Updated

2024-04-25

·

CVE-2023-46944

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitKraken GitLens versions prior to 14.0.0
Description The issue is related to insufficient input validation in the GitKraken GitLens plugin for Visual Studio Code, allowing an attacker to execute arbitrary code via a crafted file. This can be exploited by an attacker to gain unauthorized access and execute malicious code.
Recommendations For versions prior to 14.0.0, update to version 14.0.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the Visual Studio Code workspace trust component to minimize the risk of exploitation. Avoid using crafted files that could potentially exploit the insufficient input validation in the GitKraken GitLens plugin.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-03537
CVE-2023-46944

Affected Products

Gitkraken Gitlens
Visual Studio Code