{"id":"CVE-2024-47604","summary":"XSS vulnerability in NuGetGallery HTML attributes handling","details":"NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.","aliases":["GHSA-hq63-27r7-2j64"],"modified":"2026-08-12T03:51:12.368650531Z","published":"2024-10-01T15:26:18.383Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47604.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2024.06.21"},{"last_affected":"2024.09.25"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47604.json"},{"type":"ADVISORY","url":"https://github.com/NuGet/NuGetGallery/security/advisories/GHSA-hq63-27r7-2j64"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47604"},{"type":"FIX","url":"https://github.com/NuGet/NuGetGallery/commit/3a18689dd0de856e03d081af999783f0e6e7ca70"},{"type":"FIX","url":"https://github.com/NuGet/NuGetGallery/pull/10193"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nuget/nugetgallery","events":[{"introduced":"0"},{"fixed":"3a18689dd0de856e03d081af999783f0e6e7ca70"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2024.05.28","v2023.04.25","v2023.02.27","v2022.10.19","v2021.04.08","v2020.06.09","v2019.06.24","v2019.01.14","v2018.11.12","v2018.10.20","v2018.11.05","v2018.08.20","v2018.09.25","v2018.08.08","v2018.08.01","v2018.07.16","v2018.11.06","v2018.05.21","v2018.05.08","v2018.02.22","v2018.04.25","v2018.04.05","v2018.03.12","v2018.01.29","v2018.01.08","v2017.11.27","v2017.10.31","v2017.10.19","v2017.09.01","v2017.08.14","v2017.06.14","v2017.04.28","v2017.03.27","v2017.03.22","v2017.02.24","v2017.01.30","v2017.01.27","v2017.01.17","v2017.01","v2016.12","3.0.474-r-master-NuGet","3.0.624-r-master","3.0.623-r-master","3.0.621-r-master-ApiApps","3.0.610-r-master-ApiApps","3.0.608-r-master-ApiApps","3.0.606-r-master-ApiApps","3.0.601-r-master-ApiApps","3.0.269-r-develop-octov3-1-ApiApps","3.0.578-r-master-NuGet","3.0.576-r-master-NuGet","3.0.570-r-master-NuGet","3.0.554-r-master-NuGet","3.0.543-r-master-NuGet","3.0.540-r-master-NuGet","3.0.525-r-master-NuGet","3.0.524-r-master-NuGet","3.0.514-r-master-NuGet","3.0.510-r-master-NuGet","3.0.507-r-master-NuGet","3.0.506-r-master-NuGet","3.0.501-r-master-NuGet","3.0.490-r-master-NuGet","3.0.434-r4-master-NuGet","3.0.393-r-master","iters/7/start","iters/6/qa","iters/6/start","iters/5/qa","iters/zold/2013Jul19","iters/zold/2012Jun04@0000","iters/zold/2.0","iters/zold/1.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47604.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}