6.5

CVE-2019-0757

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Visual Studio 2017 Version -
   Apple ≫ macOS Version -
Microsoft ≫ Nuget Version 4.3.1
Microsoft ≫ Nuget Version 4.4.2
Microsoft ≫ Nuget Version 4.5.2
Microsoft ≫ Nuget Version 4.6.3
Microsoft ≫ Nuget Version 4.7.2
Microsoft ≫ Nuget Version 4.8.2
Microsoft ≫ Nuget Version 4.9.4
Mono-project ≫ Mono Framework Version 5.18.0.223
Mono-project ≫ Mono Framework Version 5.20.0
Microsoft ≫ .Net Core Sdk Version 1.1
   Microsoft ≫ .Net Core Version 1.0
   Microsoft ≫ .Net Core Version 1.1
Microsoft ≫ .Net Core Sdk Version 2.1.500
   Microsoft ≫ .Net Core Version 2.1
Microsoft ≫ .Net Core Sdk Version 2.2.100
   Microsoft ≫ .Net Core Version 2.2
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.7% 0.84
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://access.redhat.com/errata/RHSA-2019:1259
Third Party Advisory
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0757
Patch
Vendor Advisory