Vulnerability in Stripe for Visual Studio Code < 1.7.3
High7.5CVE-2021-21420 · Published Mar 31, 2021 · updated Apr 1, 2021
### Impact A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. The update addresses the vulnerability by modifying the way the extension validates its settings. There has been no evidence of exploitation of this vulnerability. ### Recommendation Upgrade to Stripe for Visual Studio Code 1.7.3 ### Acknowledgments Thanks to [David Dworken](https://daviddworken.com) for reporting the issue. ### For more information Email us at [security@stripe.com](mailto:security@stripe.com)
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vscode-stripe Product | < 1.7.3 | 1.7.3 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
More Stripe advisories
All Stripe| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 52024 | Vulnerability in stripe-cli >= 1.11.1 | High7.5 | 1.21.3 |
| May 102022 | Smokescreen SSRF via deny list bypass (square brackets) | Medium5.3 | 0.0.4 |
| Apr 72022 | Smokescreen SSRF via deny list bypass | Medium5.8 | 0.0.3 |
| Mar 92022 | Vulnerability in Stripe CLI < 1.7.13 | Medium | 1.7.13 |