Loading HuntDB...

GHSA-3hcm-6fjc-47qq

GitHub Security Advisory

NuGet Package Manager Tampering Vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default `obj`), aka 'NuGet Package Manager Tampering Vulnerability'.

Affected Packages

NuGet NuGet.Commands
Affected versions: 5.0.0 (fixed in 5.0.2)

Related CVEs

Key Information

GHSA ID
GHSA-3hcm-6fjc-47qq
Published
May 24, 2022 10:28 PM
Last Modified
March 24, 2024 8:28 PM
CVSS Score
5.0 /10
Primary Ecosystem
NuGet
Primary Package
NuGet.Commands
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 14, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.