[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Nuget Package Manager Tampering Vulnerability in ASP.NET core- CVE-2019-0757

ID: oval:org.secpod.oval:def:65714Date: (C)2020-09-29   (M)2023-11-29
Class: VULNERABILITYFamily: windows




A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure. An attacker who successfully exploited this vulnerability could potentially modify files and folders that are unpackaged on a system. To exploit this vulnerability, an attacker would need to log on to the affected system and tamper with the folder contents of a package prior to building or installation of an application.

Platform:
Microsoft Windows 10
Microsoft Windows 7
Microsoft Windows 8.1
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Product:
Microsoft ASP .NET core 1.0
Microsoft ASP .NET core 1.1
Microsoft ASP .NET core 2.1
Microsoft ASP .NET core 2.2
Reference:
CVE-2019-0757
CVE    1
CVE-2019-0757
CPE    8
cpe:/a:microsoft:asp_.net_core:1.1:::x64
cpe:/a:microsoft:asp_.net_core:1.1:::x86
cpe:/a:microsoft:asp_.net_core:2.1:::x64
cpe:/a:microsoft:asp_.net_core:2.1:::x86
...

© SecPod Technologies