CVE-2019-0757
dotnet: NuGet Tampering Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Existe una vulnerabilidad de manipulación en NuGet Package Manager para Linux y Mac que podría permitir que un atacante autenticado modifique la estructura de carpetas de un paquete de NuGet, también conocida como 'NuGet Package Manager Tampering Vulnerability'.
A flaw was found in dotnet. A tampering vulnerability exists in NuGet software when executed in a Linux or Mac environment. An attacker who successfully exploits the vulnerability could run arbitrary code in the context of the current user. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-26 CVE Reserved
- 2019-03-13 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0757 | 2022-04-11 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:1259 | 2022-04-11 | |
https://access.redhat.com/security/cve/CVE-2019-0757 | 2019-05-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1685475 | 2019-05-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Visual Studio 2017 Search vendor "Microsoft" for product "Visual Studio 2017" | - | - |
Affected
| in | Apple Search vendor "Apple" | Macos Search vendor "Apple" for product "Macos" | - | - |
Safe
|
Microsoft Search vendor "Microsoft" | .net Core Sdk Search vendor "Microsoft" for product ".net Core Sdk" | 1.1 Search vendor "Microsoft" for product ".net Core Sdk" and version "1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | .net Core Search vendor "Microsoft" for product ".net Core" | 1.0 Search vendor "Microsoft" for product ".net Core" and version "1.0" | - |
Safe
|
Microsoft Search vendor "Microsoft" | .net Core Sdk Search vendor "Microsoft" for product ".net Core Sdk" | 1.1 Search vendor "Microsoft" for product ".net Core Sdk" and version "1.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | .net Core Search vendor "Microsoft" for product ".net Core" | 1.1 Search vendor "Microsoft" for product ".net Core" and version "1.1" | - |
Safe
|
Microsoft Search vendor "Microsoft" | .net Core Sdk Search vendor "Microsoft" for product ".net Core Sdk" | 2.1.500 Search vendor "Microsoft" for product ".net Core Sdk" and version "2.1.500" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | .net Core Search vendor "Microsoft" for product ".net Core" | 2.1 Search vendor "Microsoft" for product ".net Core" and version "2.1" | - |
Safe
|
Microsoft Search vendor "Microsoft" | .net Core Sdk Search vendor "Microsoft" for product ".net Core Sdk" | 2.2.100 Search vendor "Microsoft" for product ".net Core Sdk" and version "2.2.100" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | .net Core Search vendor "Microsoft" for product ".net Core" | 2.2 Search vendor "Microsoft" for product ".net Core" and version "2.2" | - |
Safe
|
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.3.1 Search vendor "Microsoft" for product "Nuget" and version "4.3.1" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.4.2 Search vendor "Microsoft" for product "Nuget" and version "4.4.2" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.5.2 Search vendor "Microsoft" for product "Nuget" and version "4.5.2" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.6.3 Search vendor "Microsoft" for product "Nuget" and version "4.6.3" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.7.2 Search vendor "Microsoft" for product "Nuget" and version "4.7.2" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.8.2 Search vendor "Microsoft" for product "Nuget" and version "4.8.2" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Nuget Search vendor "Microsoft" for product "Nuget" | 4.9.4 Search vendor "Microsoft" for product "Nuget" and version "4.9.4" | - |
Affected
| ||||||
Mono-project Search vendor "Mono-project" | Mono Framework Search vendor "Mono-project" for product "Mono Framework" | 5.18.0.223 Search vendor "Mono-project" for product "Mono Framework" and version "5.18.0.223" | - |
Affected
| ||||||
Mono-project Search vendor "Mono-project" | Mono Framework Search vendor "Mono-project" for product "Mono Framework" | 5.20.0 Search vendor "Mono-project" for product "Mono Framework" and version "5.20.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | 8.0 Search vendor "Redhat" for product "Enterprise Linux" and version "8.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 8.1 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 8.2 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Eus Search vendor "Redhat" for product "Enterprise Linux Eus" | 8.4 Search vendor "Redhat" for product "Enterprise Linux Eus" and version "8.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 8.2 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "8.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Aus Search vendor "Redhat" for product "Enterprise Linux Server Aus" | 8.4 Search vendor "Redhat" for product "Enterprise Linux Server Aus" and version "8.4" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 8.2 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "8.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Server Tus Search vendor "Redhat" for product "Enterprise Linux Server Tus" | 8.4 Search vendor "Redhat" for product "Enterprise Linux Server Tus" and version "8.4" | - |
Affected
|