Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-1340 - NuGet Gallery Spoofing Vulnerability #45

Open
joelverhagen opened this issue Jun 9, 2020 · 0 comments
Open

CVE-2020-1340 - NuGet Gallery Spoofing Vulnerability #45

joelverhagen opened this issue Jun 9, 2020 · 0 comments
Labels

Comments

@joelverhagen
Copy link
Member

A spoofing vulnerability exists when the NuGet Gallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content.

To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page.

The security update addresses the vulnerability by correcting how NuGet Gallery sanitizes input.

MSRC Security Guidance: CVE-2020-1340
Security Update: v2020.06.09

@NuGet NuGet locked as resolved and limited conversation to collaborators Jun 9, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

1 participant