A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka Microsoft Visual Studio Spoofing Vulnerability.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Visual_studio_2017 | Microsoft | 15.1 (including) | 15.8 (including) |
Visual_studio_2019 | Microsoft | 16.0 (including) | 16.3 (including) |