CVE-2019-0757

Source
https://cve.org/CVERecord?id=CVE-2019-0757
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0757.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-0757
Downstream
Published
2019-04-09T02:29:00.600Z
Modified
2026-07-08T05:54:54.759789623Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.

Database specific
{
    "unresolved_ranges": [
        {
            "cpes": [
                "cpe:2.3:a:microsoft:nuget:4.3.1:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.4.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.5.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.6.3:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.7.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.8.2:*:*:*:*:*:*:*",
                "cpe:2.3:a:microsoft:nuget:4.9.4:*:*:*:*:*:*:*"
            ],
            "vendor_product": "microsoft:nuget",
            "extracted_events": [
                {
                    "introduced": "4.3.1"
                },
                {
                    "last_affected": "4.3.1"
                },
                {
                    "introduced": "4.4.2"
                },
                {
                    "last_affected": "4.4.2"
                },
                {
                    "introduced": "4.5.2"
                },
                {
                    "last_affected": "4.5.2"
                },
                {
                    "introduced": "4.6.3"
                },
                {
                    "last_affected": "4.6.3"
                },
                {
                    "introduced": "4.7.2"
                },
                {
                    "last_affected": "4.7.2"
                },
                {
                    "introduced": "4.8.2"
                },
                {
                    "last_affected": "4.8.2"
                },
                {
                    "introduced": "4.9.4"
                },
                {
                    "last_affected": "4.9.4"
                }
            ],
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:a:mono-project:mono_framework:5.18.0.223:*:*:*:*:*:*:*",
                "cpe:2.3:a:mono-project:mono_framework:5.20.0:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "5.18.0.223"
                },
                {
                    "last_affected": "5.18.0.223"
                },
                {
                    "introduced": "5.20.0"
                },
                {
                    "last_affected": "5.20.0"
                }
            ],
            "vendor_product": "mono-project:mono_framework",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "8.1"
                },
                {
                    "last_affected": "8.1"
                },
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_eus",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server_aus",
            "source": "CPE_STRING"
        },
        {
            "cpes": [
                "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*",
                "cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*"
            ],
            "extracted_events": [
                {
                    "introduced": "8.2"
                },
                {
                    "last_affected": "8.2"
                },
                {
                    "introduced": "8.4"
                },
                {
                    "last_affected": "8.4"
                }
            ],
            "vendor_product": "redhat:enterprise_linux_server_tus",
            "source": "CPE_STRING"
        }
    ]
}
References

Affected packages

Git / github.com/dotnet/cli

Affected ranges

Type
GIT
Repo
https://github.com/dotnet/cli
Events
Database specific
{
    "cpe": [
        "cpe:2.3:a:microsoft:.net_core_sdk:1.1:*:*:*:*:*:*:*",
        "cpe:2.3:a:microsoft:.net_core_sdk:2.1.500:*:*:*:*:*:*:*",
        "cpe:2.3:a:microsoft:.net_core_sdk:2.2.100:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "1.1"
        },
        {
            "last_affected": "1.1"
        },
        {
            "introduced": "2.1.500"
        },
        {
            "last_affected": "2.1.500"
        },
        {
            "introduced": "2.2.100"
        },
        {
            "last_affected": "2.2.100"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

1.*
1.1
2.*
2.1.500
2.2.100

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0757.json"

Git / github.com/dotnet/core

Affected ranges

Type
GIT
Repo
https://github.com/dotnet/core
Events
Database specific
{
    "cpe": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "8.0"
        },
        {
            "last_affected": "8.0"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

8.*
8.0
v6.*
v6.0.25
v7.*
v7.0.14
v8.*
v8.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-0757.json"