Cleartext transmission of sensitive information in Microsoft Visual Studio Code Live Share extension - CVE-2020-1343
Published: June 10, 2020
Vulnerability identifier: #VU28926
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1343
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A remote attacker with ability to intercept network traffic can gain access to sensitive data, such as token in plain text.
Affected software
Microsoft Visual Studio Code Live Share extension
How to mitigate CVE-2020-1343
Install updates from vendor's website.
Microsoft Visual Studio Code Live Share extension - update to 1.0.2274