Advisory #36
TitleRPM Specfile support in VSCode remote code execution via crafted workspace configuration
CVE IDCVE-2021-31414
VendorLaurent Tréguier
Affected productRPM Specfile support in VSCode
Affected versions- 0.3.1
Vulnerability typeCWE-284 (Improper Access Control)
DescriptionRPM Specfile support in VSCode has a vulnerability that allows a crafted workspace folder to execute arbitrary binaries, which leads remote code execution.
StatusFixed in 0.3.2
RecommendationUpdate to 0.3.2 or above.