Visual Studio Code Server Files Detected

medium Web App Scanning Plugin ID 113850

Synopsis

Visual Studio Code Server Files Detected

Description

Visual Studio Code is a popular source-code editor provided by Microsoft, with extensions offering a variety of extra functionality including remote workspace access via ssh. Use of this remote workflow creates a hidden directory named .vscode-server on the remote server which may be exposed with the web application configuration and can contain files, technologies and versions, user activity, binaries, scripts and other potentially sensitive information. This may be used to further facilitate attacks against the server.

Solution

Review the contents of the discovered .vscode-server directory and remove sensitive content, and/or adjust the web server's access controls to limit access to sensitive material

See Also

https://code.visualstudio.com/docs/remote/ssh

Plugin Details

Severity: Medium

ID: 113850

Type: remote

Published: 5/5/2023

Updated: 5/5/2023

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information