Known vulnerabilities in Visual Studio Code Maven extension
Vendor:
Microsoft
Software:
Visual Studio Code Maven extension
Software CPE:
cpe:2.3:a:microsoft:vscode-maven:*:*:*:*:*:*:*:*
Website:
https://www.microsoft.com
Total vulnerabilities:
2
Public exploits:
1
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
0.45.3
0.45.2
0.45.1
0.45.0
0.44.0
0.43.0
0.42.0
0.41.0
0.40.4
0.40.3
0.40.2
0.40.1
0.40.0
0.39.2
0.39.1
0.39.0
0.38.0
0.37.0
0.36.0
0.35.2
0.35.1
0.35.0
0.34.2
0.34.1
0.34.0
0.33.0
0.32.2
0.32.1
0.32.0
0.31.0
0.30.1
0.30.0
0.29.0
0.28.0
0.27.0
0.26.0
0.25.0
0.24.2
0.24.1
0.24.0
0.23.0
0.22.0
0.21.4
0.21.3
0.21.2
0.21.1
0.21.0
0.20.2
0.20.1
0.20.0
0.19.1
0.19.0
0.18.2
0.18.1
0.18.0
0.17.1
0.17.0
0.16.2
0.16.1
0.16.0
0.15.2
0.15.1
0.15.0
0.14.2
0.14.1
0.14.0
0.13.0
0.12.1
0.12.0
0.11.3
0.11.2
0.11.1
0.11.0
0.10.0
0.9.2
0.9.1
0.9.0
0.8.0
0.7.0
0.6.0
0.5.2
0.5.1
0.5.0
0.4.0
0.3.0
0.2.1
0.2.0
0.1.4
0.1.3
0.1.2
0.1.1
0.1.0
0.0.6
0.0.5
0.0.4
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU68307 - Improper Control of Generation of Code ('Code Injection') CVE-2022-42889 |
CWE-94 | High | 0.40.2 | 14.10.2022 |
SB2022101405 SB2022102709 SB2022110306 and 91 more |
||
| #VU45618 - Improper input validation CVE-2020-0604 |
CWE-20 | High | 0.24.0 | 12.08.2020 |
SB2020081232 |