CVE-2020-1343 describes an information disclosure vulnerability in the Microsoft Visual Studio Code Live Share Extension. This flaw allows sensitive tokens to be exposed in plain text, potentially compromising user data. With a CVSS score of 5.9 (Medium), this vulnerability has a network attack vector and low attack complexity, enabling an unauthenticated attacker to achieve high confidentiality impact without user interaction. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it received limited community discussion and media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:visual_studio_live_share:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.