CVE-2019-0757

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-0757
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0757.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-0757
Published
2019-04-09T02:29:00Z
Modified
2025-02-19T02:39:11.311393Z
Downstream
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.

References

Affected packages

Git / github.com/dotnet/cli

Affected ranges

Type
GIT
Repo
https://github.com/dotnet/cli
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Type
GIT
Repo
https://github.com/dotnet/core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

release/2.*

release/2.0.0
release/2.1
release/2.1.1xx
release/2.1.2xx
release/2.1.3xx
release/2.1.4xx

v1.*

v1.0.0
v1.0.0-preview2
v1.0.0-preview2.0.1
v1.0.0-preview3-004056
v1.0.0-rc1
v1.0.0-rc2
v1.0.0-rc3-004517
v1.0.0-rc4-004771
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.1
v1.1.0
v1.1.0-preview1
v1.1.0-preview1-005051
v1.1.0-preview1-005077

v2.*

v2.0.0
v2.0.0-preview1
v2.0.0-preview2
v2.0.2
v2.0.3
v2.1.1-preview-007183
v2.1.100
v2.1.101
v2.1.102
v2.1.103
v2.1.104
v2.1.105
v2.1.2
v2.1.200
v2.1.201
v2.1.202
v2.1.3
v2.1.300
v2.1.300-preview1-008174
v2.1.300-preview2-008530
v2.1.300-rc1-008673
v2.1.301
v2.1.301+dependencies
v2.1.302
v2.1.4
v2.1.400
v2.1.401
v2.1.402
v2.1.402+dependencies
v2.1.403
v2.1.403+dependencies
v2.1.500
v2.1.500+dependencies
v2.1.500-preview-009335
v2.1.500-preview-009335+dependencies