CVE-2020-1340

Source
https://cve.org/CVERecord?id=CVE-2020-1340
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1340.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-1340
Published
2020-06-09T20:15:21.833Z
Modified
2026-08-07T15:11:53.986352Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery Spoofing Vulnerability'.

References

Affected packages

Git / github.com/nuget/nugetgallery

Affected ranges

Type
GIT
Repo
https://github.com/nuget/nugetgallery
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:microsoft:nugetgallery:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2020.06.09"
        }
    ]
}

Affected versions

3.*
3.0.269-r-develop-octov3-1-ApiApps
3.0.393-r-master
3.0.434-r4-master-NuGet
3.0.474-r-master-NuGet
3.0.490-r-master-NuGet
3.0.501-r-master-NuGet
3.0.506-r-master-NuGet
3.0.507-r-master-NuGet
3.0.510-r-master-NuGet
3.0.514-r-master-NuGet
3.0.524-r-master-NuGet
3.0.525-r-master-NuGet
3.0.540-r-master-NuGet
3.0.543-r-master-NuGet
3.0.554-r-master-NuGet
3.0.570-r-master-NuGet
3.0.576-r-master-NuGet
3.0.578-r-master-NuGet
3.0.601-r-master-ApiApps
3.0.606-r-master-ApiApps
3.0.608-r-master-ApiApps
3.0.610-r-master-ApiApps
3.0.621-r-master-ApiApps
3.0.623-r-master
3.0.624-r-master
Other
iters/5/qa
iters/6/qa
iters/6/start
iters/7/start
iters/zold/2012Jun04@0000
iters/zold/2013Jul19
iters/zold/1.*
iters/zold/1.8
iters/zold/2.*
iters/zold/2.0
v2016.*
v2016.12
v2017.*
v2017.01
v2017.01.17
v2017.01.27
v2017.01.30
v2017.02.24
v2017.03.22
v2017.03.27
v2017.04.28
v2017.06.14
v2017.08.14
v2017.09.01
v2017.10.19
v2017.10.31
v2017.11.27
v2018.*
v2018.01.08
v2018.01.29
v2018.02.22
v2018.03.12
v2018.04.05
v2018.04.25
v2018.05.08
v2018.05.21
v2018.07.16
v2018.08.01
v2018.08.08
v2018.08.20
v2018.09.25
v2018.10.20
v2018.11.05
v2018.11.06
v2018.11.12
v2019.*
v2019.01.14
v2019.06.24

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1340.json"