Cleartext transmission of sensitive information in Microsoft Visual Studio Code Live Share extension - CVE-2020-1343

 

Cleartext transmission of sensitive information in Microsoft Visual Studio Code Live Share extension - CVE-2020-1343

Published: June 10, 2020


Vulnerability identifier: #VU28926
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-1343
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information. A remote attacker with ability to intercept network traffic can gain access to sensitive data, such as token in plain text.


Affected software

Microsoft Visual Studio Code Live Share extension

How to mitigate CVE-2020-1343

Install updates from vendor's website.

Microsoft Visual Studio Code Live Share extension - update to 1.0.2274

External References

Related Security Bulletins