CVE-2019-0757
high-risk
Published 2019-04-09
A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify a NuGet package's folder structure, aka 'NuGet Package Manager Tampering Vulnerability'.
Do I need to act?
~
5.4% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
6
CVSS 6.5/10
Medium
NETWORK
/ LOW complexity
Affected Products (20)
Nuget
Nuget
Nuget
Nuget
Nuget
Nuget
Nuget
Mono Framework
Mono Framework
.Net Core Sdk
.Net Core Sdk
.Net Core Sdk
Affected Vendors
References (4)
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1259
Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:1259
52
/ 100
high-risk
Severity
24/34 · High
Exploitability
8/34 · Low
Exposure
20/34 · Moderate