VDB
CVE-2021-22539
CVE-2021-22539
PUBLISHED
CVSS 8.199999809265137 HIGH
An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel allows the workspace path to lint *.bzl files to be set via this config file. As such the attacker is able to execute any executable on the system through vscode-bazel. We recommend upgrading to version 0.4.1 or above.
EPSS 0.31% · 24.1th percentile
Risk Scores
CVSS 3.1
8.199999809265137
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS Score
0.31%
24.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bazel | 0.1.0 | |
| Google LLC | VSCode-Bazel | * |
Timeline
- Apr 16, 2021 EPSS Score
- Apr 16, 2021 CVE Published
- Jun 25, 2021 EPSS Score
- Aug 27, 2021 EPSS Score
- Oct 28, 2021 EPSS Score
- Dec 30, 2021 EPSS Score
- Mar 3, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 5, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Nov 10, 2022 EPSS Score