One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 6399396
Date de publication 2022-08-18 19:15:14 (vue: 2022-08-18 21:06:57)
Titre CVE-2022-35976
Texte The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A specially crafted kubeconfig leads to arbitrary code execution on behalf of the user running VSCode. Users relying on kubeconfigs that are generated or altered by other processes or users are affected by this issue. Please note that the vulnerability is specific to this extension, and the same kubeconfig would not result in arbitrary code execution when used with kubectl. Using only trust-worthy kubeconfigs is a safe mitigation. However, updating to the latest version of the extension is still highly recommended.
Envoyé Oui
Condensat 2022 35976 affected altered arbitrary are behalf clusters code communicate crafted cve execution extension generated gitops highly however issue kubeconfig kubeconfigs kubectl kubernetes latest leads mitigation not note only order other please processes recommended relies relying result running safe same specially specific tools trust updating used user users using version vscode vulnerability when worthy would
Tags Vulnerability Guideline
Stories Uber
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: