U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-24441

Change History

Initial Analysis by NIST 12/02/2022 2:16:01 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:snyk:snyk_cli:*:*:*:*:*:*:*:* versions up to (excluding) 1.1064.0
     *cpe:2.3:a:snyk:snyk_language_server:*:*:*:*:*:*:*:* versions up to (including) 20221109.114426
     *cpe:2.3:a:snyk:snyk_security:*:*:*:*:*:visual_studio:*:* versions up to (including) 1.1.30
     *cpe:2.3:a:snyk:snyk_security:*:*:*:*:*:visual_studio_code:*:* versions up to (including) 1.8.0
     *cpe:2.3:a:snyk:snyk_security:*:*:*:*:*:intellij:*:* versions up to (including) 2.4.47
     *cpe:2.3:a:snyk:snyk_security:*:*:*:*:*:eclipse:*:* versions up to (including) 20221115.132308
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-94
Changed Reference Type
https://github.com/snyk/snyk-eclipse-plugin/commit/b5a8bce25a359ced75f83a729fc6b2393fc9a495 No Types Assigned
https://github.com/snyk/snyk-eclipse-plugin/commit/b5a8bce25a359ced75f83a729fc6b2393fc9a495 Patch, Third Party Advisory
Changed Reference Type
https://github.com/snyk/snyk-intellij-plugin/commit/56682f4ba6081ce1d95cb980cbfacd3809a826f4 No Types Assigned
https://github.com/snyk/snyk-intellij-plugin/commit/56682f4ba6081ce1d95cb980cbfacd3809a826f4 Patch, Third Party Advisory
Changed Reference Type
https://github.com/snyk/snyk-ls/commit/b3229f0142f782871aa72d1a7dcf417546d568ed No Types Assigned
https://github.com/snyk/snyk-ls/commit/b3229f0142f782871aa72d1a7dcf417546d568ed Patch, Third Party Advisory
Changed Reference Type
https://github.com/snyk/snyk-visual-studio-plugin/commit/0b53dbbd4a3153c3ef9aaf797af3b5caad0f731a No Types Assigned
https://github.com/snyk/snyk-visual-studio-plugin/commit/0b53dbbd4a3153c3ef9aaf797af3b5caad0f731a Patch, Third Party Advisory
Changed Reference Type
https://github.com/snyk/vscode-extension/commit/0db3b4240be0db6a0a5c6d02c0d4231a2c4ba708 No Types Assigned
https://github.com/snyk/vscode-extension/commit/0db3b4240be0db6a0a5c6d02c0d4231a2c4ba708 Patch, Third Party Advisory
Changed Reference Type
https://security.snyk.io/vuln/SNYK-JS-SNYK-3111871 No Types Assigned
https://security.snyk.io/vuln/SNYK-JS-SNYK-3111871 Exploit, Patch, Vendor Advisory
Changed Reference Type
https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution/ No Types Assigned
https://www.imperva.com/blog/how-scanning-your-projects-for-security-issues-can-lead-to-remote-code-execution/ Exploit, Third Party Advisory