Visual Studio Code Configuration Detected

medium Web App Scanning Plugin ID 113201

Synopsis

Visual Studio Code Configuration Detected

Description

Visual Studio Code is a popular source-code editor provided by Microsoft, with extensions offering a variety of extra functionality covering amongst others remote file access, credentials and launch configurations. Configurations may be located inside a hidden directory named .vscode. When exposed with the web application configuration, these configuration files may expose sensitive information which may be used by an attacker to gain unauthorized access.

Solution

Review the contents of the discovered .vscode directory and remove sensitive content, and/or adjust the web server's access controls to limit access to sensitive material.

See Also

https://code.visualstudio.com/docs/getstarted/settings

Plugin Details

Severity: Medium

ID: 113201

Type: remote

Published: 3/24/2022

Updated: 6/28/2022

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information