CVE-2019-0757High

NuGet Package Manager Tampering Vulnerability

Published
March 12, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure. An attacker who successfully exploited this vulnerability could potentially modify files and folders that are unpackaged on a system. To exploit this vulnerability, an attacker would need to log on to the affected system and tamper with the folder contents of a package prior to building or installation of an application. The security update addresses the vulnerability by correcting permissions on folders inside the NuGet packages folder structure.

🎯 Affected products14

  • .NET Core SDK 1.1 on .NET Core 1.0
  • .NET Core SDK 1.1 on .NET Core 1.1
  • .NET Core SDK 2.1.500 on .NET Core 2.1
  • .NET Core SDK 2.2.100 on .NET Core 2.2
  • Mono Framework Version 5.18.0.223
  • Mono Framework Version 5.20.0
  • Nuget 4.3.1
  • Nuget 4.4.2
  • Nuget 4.5.2
  • Nuget 4.6.3
  • Nuget 4.7.2
  • Nuget 4.8.2
  • Nuget 4.9.4
  • Visual Studio 2017 for Mac

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (2)