CVE-2024-9145

CVSS V2 None CVSS V3 None
Description
Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command injection if the user opens a maliciously crafted Dockerfile located in a path that has been marked as a "trusted folder" within Visual Studio Code, and initiates a manual scan of the file.
Overview
  • CVE ID
  • CVE-2024-9145
  • Assigner
  • Wiz
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-01T07:23:03.891Z
  • Last Modified Date
  • 2024-10-01T13:46:57.430Z
History
Created Old Value New Value Data Type Notes
2024-10-06 22:12:53 Added to TrackCVE