{"id":"CVE-2020-1340","details":"A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values, aka 'NuGetGallery Spoofing Vulnerability'.","modified":"2026-08-07T15:11:53.986352Z","published":"2020-06-09T20:15:21.833Z","references":[{"type":"FIX","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1340"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nuget/nugetgallery","events":[{"introduced":"0"},{"fixed":"6d955d13396271d3fe86d8b54790752177d59591"}],"database_specific":{"cpe":"cpe:2.3:a:microsoft:nugetgallery:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2020.06.09"}],"source":"CPE_RANGE"}}],"versions":["v2019.06.24","v2019.01.14","v2018.11.12","v2018.10.20","v2018.11.05","v2018.08.20","v2018.09.25","v2018.08.08","v2018.08.01","v2018.07.16","v2018.11.06","v2018.05.21","v2018.05.08","v2018.02.22","v2018.04.25","v2018.04.05","v2018.03.12","v2018.01.29","v2018.01.08","v2017.11.27","v2017.10.31","v2017.10.19","v2017.09.01","v2017.08.14","v2017.06.14","v2017.04.28","v2017.03.27","v2017.03.22","v2017.02.24","v2017.01.30","v2017.01.27","v2017.01.17","v2017.01","v2016.12","3.0.474-r-master-NuGet","3.0.624-r-master","3.0.623-r-master","3.0.621-r-master-ApiApps","3.0.610-r-master-ApiApps","3.0.608-r-master-ApiApps","3.0.606-r-master-ApiApps","3.0.601-r-master-ApiApps","3.0.269-r-develop-octov3-1-ApiApps","3.0.578-r-master-NuGet","3.0.576-r-master-NuGet","3.0.570-r-master-NuGet","3.0.554-r-master-NuGet","3.0.543-r-master-NuGet","3.0.540-r-master-NuGet","3.0.525-r-master-NuGet","3.0.524-r-master-NuGet","3.0.514-r-master-NuGet","3.0.510-r-master-NuGet","3.0.507-r-master-NuGet","3.0.506-r-master-NuGet","3.0.501-r-master-NuGet","3.0.490-r-master-NuGet","3.0.434-r4-master-NuGet","3.0.393-r-master","iters/7/start","iters/6/qa","iters/6/start","iters/5/qa","iters/zold/2013Jul19","iters/zold/2012Jun04@0000","iters/zold/2.0","iters/zold/1.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1340.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}