{"id":"CVE-2019-0976","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-0976","summary":"NuGet Package Manager Tampering Vulnerability","details":"A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default `obj`), aka 'NuGet Package Manager Tampering Vulnerability'.","published":"2022-05-24T22:28:08Z","modified":"2024-03-24T20:41:49.187251Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"NuGet.Commands","fixedVersion":"5.0.2"}],"fix":{"url":"https://github.com/NuGet/NuGet.Client/commit/e32a2ea7096debd3e513188f6779bb1041593326","label":"NuGet/NuGet.Client@e32a2ea"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0976"},{"type":"WEB","url":"https://github.com/NuGet/Home/issues/7908"},{"type":"WEB","url":"https://github.com/NuGet/NuGet.Client/commit/e32a2ea7096debd3e513188f6779bb1041593326"},{"type":"PACKAGE","url":"https://github.com/NuGet/NuGet.Client"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0976"},{"type":"WEB","url":"https://web.archive.org/web/20200227075944/http://www.securityfocus.com/bid/108210"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-03-24T20:41:49.187251Z"}}