Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-0976

Опубликовано: 14 мая 2019
Источник: msrc
EPSS Низкий

Описание

NuGet Package Manager Tampering Vulnerability

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default “obj”). An attacker who successfully exploited this vulnerability could potentially modify files and folders that impact binaries created as part of building a project.

To exploit this vulnerability, an attacker would need to log on to the affected system and tamper with the intermediate build folder which may impact the output of future builds of that project.

The security update addresses the vulnerability by correcting permissions on the intermediate build folder.

Обновления

ПродуктСтатьяОбновление
Nuget 5.0.2

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 50%
0.00274
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 6 лет назад

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'.

CVSS3: 5.5
nvd
больше 6 лет назад

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default "obj"), aka 'NuGet Package Manager Tampering Vulnerability'.

CVSS3: 5.5
debian
больше 6 лет назад

A tampering vulnerability exists in the NuGet Package Manager for Linu ...

CVSS3: 5.5
github
больше 3 лет назад

NuGet Package Manager Tampering Vulnerability

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость системы управления пакетами NuGet, связанная с недостатками контроля доступа, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 50%
0.00274
Низкий