Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35995
HistoryJun 15, 2022 - 5:58 a.m.

Information Disclosure

2022-06-1505:58:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

0.003 Low

EPSS

Percentile

66.4%

NuGet.org is vulnerable to information disclosure. The vulnerability exists in the ExecuteCommand function in SetApiKeyCommand.cs due to a lack of sanitization in api key which allows an attacker to get access to sensitive information.

References