Lucene search

K
githubGitHub Advisory DatabaseGHSA-3HCM-6FJC-47QQ
HistoryMay 24, 2022 - 10:28 p.m.

NuGet Package Manager Tampering Vulnerability

2022-05-2422:28:08
CWE-732
GitHub Advisory Database
github.com
6
nuget
package manager
tampering
vulnerability
linux
mac
authenticated attacker

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.8%

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default obj), aka ‘NuGet Package Manager Tampering Vulnerability’.

Affected configurations

Vulners
Node
nuget.commandsRange5.0.05.0.2
VendorProductVersionCPE
*nuget.commands*cpe:2.3:a:*:nuget.commands:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

Low

EPSS

0

Percentile

9.8%