NuGet / Announcements

Subscribe to this repo to be notified of upcoming proposals and other important changes to NuGet
81 stars 7 forks source link

CVE-2020-1340 - NuGet Gallery Spoofing Vulnerability #45

Open joelverhagen opened 4 years ago

joelverhagen commented 4 years ago

A spoofing vulnerability exists when the NuGet Gallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content.

To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page.

The security update addresses the vulnerability by correcting how NuGet Gallery sanitizes input.

MSRC Security Guidance: CVE-2020-1340 Security Update: v2020.06.09