NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Markdown content. While the platform properly filters out JavaScript from standard links, it does not adequately sanitize autolinks. This oversight allows attackers to exploit autolinks as a vector for Cross-Site Scripting (XSS) attacks. When a user inputs a Markdown autolink such as `<javascript:alert(1)>`, the link is rendered without proper sanitization. This means that the JavaScript code within the autolink can be executed by the browser, leading to an XSS attack. Version 2024.05.28 contains a patch for this issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-12T14:27:40.184Z
Updated: 2024-08-02T03:50:55.991Z
Reserved: 2024-06-05T20:10:46.497Z
Link: CVE-2024-37304
Vulnrichment
Updated: 2024-06-12T17:58:23.676Z
NVD
Status : Awaiting Analysis
Published: 2024-06-12T15:15:52.910
Modified: 2024-06-13T18:36:09.010
Link: CVE-2024-37304
Redhat
No data.