Skip to content
MicrosoftGHSA-fj7x-w8c2-xx4c

Information Disclosure Vulnerability

MediumCVE-2022-41042 · Published Oct 11, 2022

An information disclosure vulnerability exists in VS Code 1.71 and earlier versions. If an attacker is able to run arbitrary scripts inside of a webview (either created by an extension or by core VS Code), the attacker could bypass the local resource roots check to read arbitrary files on the ### Patches The fix is available starting with **VS Code 1.71.1**. The [fix](https://github.com/microsoft/vscode/commit/fad9089781c40e7b35e43076ca2951085aa8264d) mitigates this attack by performing input validation on the URL pointing to the repository to be cloned. ### Workarounds Only use webviews from extensions that follow proper security measures to block script injection Do not disable VS Code's default security measures in the built-in markdown preview ### References * The patch for this can be found at https://github.com/microsoft/vscode/commit/fad9089781c40e7b35e43076ca2951085aa8264d * An issue can be found at https://github.com/microsoft/vscode/issues/163326 * MSRC details for this can be found at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41042

GitHub advisory

Affected versions

PackageAffectedFixed in
vscode
Product
< 1.71.11.71.1
Details and references

More Microsoft advisories

All Microsoft
Advisory
Remote Code Execution Vulnerability
MediumJan 10, 2023
Remote Code Execution Vulnerability
HighOct 11, 2022
Elevation of Privilege Vulnerability
HighSep 14, 2022
Remote Code Execution Vulnerability
HighMay 25, 2022
Spoofing Vulnerability
HighMay 25, 2022
Elevation of Privilege Vulnerability
HighMay 25, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.