You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A spoofing vulnerability exists when the NuGet Gallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content.
To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page.
The security update addresses the vulnerability by correcting how NuGet Gallery sanitizes input.
A spoofing vulnerability exists when the NuGet Gallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content.
To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page.
The security update addresses the vulnerability by correcting how NuGet Gallery sanitizes input.
MSRC Security Guidance: CVE-2020-1340
Security Update: v2020.06.09
The text was updated successfully, but these errors were encountered: