[CVE-2022-41042] 逃逸配置不当的 VSCode 扩展
blog.trailofbits.com | 漏洞 | CVE-2022-41042 | #vulnerability-research | #xss | #path-traversal | #vulnerability-disclosure | #trail-of-bits | #vscode | #cve-2022-41042 | #extension-security | #html-injection | #csp-bypass | #file-exfiltration | #local-file-theft
摘要
Trail of Bits 两部曲系列第一篇:披露微软 SARIF Viewer 与 Live Preview 两个 VSCode 扩展中的三个漏洞(HTML/JS 注入与路径遍历),可导致本地文件被窃取甚至 SSH 密钥泄露,并包含获 7,500 美元赏金的 CVE-2022-41042 缓解绕过。
- 发布时间
- 收录时间
Skip to content