CVE-2021-28472 describes a Remote Code Execution vulnerability within the Visual Studio Code Maven for Java Extension (microsoft/vscode-maven). This high-severity flaw, rated 7.8 CVSS, allows an unauthenticated attacker to achieve full compromise (confidentiality, integrity, availability) on a vulnerable system, requiring user interaction but with low attack complexity. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.29.0CPE matchmatch criteria | cpe:2.3:a:microsoft:vscode-maven:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.