Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Microsoft Python
cpe:2.3:a:microsoft:python:-:*:*:*:*:visual_studio_code:*:*
|
— | — |
|
Microsoft Visual_Studio_Code
cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*
|
— |
1.132.1
|