CVE-2024-9145
CVSS V2 None
CVSS V3 None
Description
Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in versions 0.13.0 up to 0.17.8 are vulnerable to local command injection if the user opens a maliciously crafted Dockerfile located in a path that has been marked as a "trusted folder" within Visual Studio Code, and initiates a manual scan of the file.
Overview
- CVE ID
- CVE-2024-9145
- Assigner
- Wiz
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-01T07:23:03.891Z
- Last Modified Date
- 2024-10-01T13:46:57.430Z
Weakness Enumerations
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-9145 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-9145 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 22:12:53 | Added to TrackCVE |