CVE-2020-1340: NuGetGallery Spoofing Vulnerability

Overview

Severity
N/A
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Jun
Released
2020-06-09
EPSS Score
0.40% (percentile: 60.7%)

Description

A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content. To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page. The security update addresses the vulnerability by correcting how NuGetGallery sanitizes input.

Affected Products (1)

Developer Tools

  • NuGetGallery

Security Updates (1)

Acknowledgments

Gabriel Thau

Revision History

  • 2020-06-09: Information published.