NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Nov 2024 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Microsoft
Microsoft nugetgallery |
|
CPEs | cpe:2.3:a:microsoft:nugetgallery:*:*:*:*:*:*:*:* | |
Vendors & Products |
Microsoft
Microsoft nugetgallery |
Tue, 01 Oct 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 01 Oct 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. | |
Title | XSS vulnerability in NuGetGallery HTML attributes handling | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-01T15:26:18.383Z
Updated: 2024-10-01T17:13:16.824Z
Reserved: 2024-09-27T20:37:22.119Z
Link: CVE-2024-47604
Vulnrichment
Updated: 2024-10-01T17:13:12.703Z
NVD
Status : Analyzed
Published: 2024-10-01T16:15:10.003
Modified: 2024-11-13T23:17:14.437
Link: CVE-2024-47604
Redhat
No data.