{"id":"GHSA-3hcm-6fjc-47qq","summary":"NuGet Package Manager Tampering Vulnerability","details":"A tampering vulnerability exists in the NuGet Package Manager for Linux and Mac that could allow an authenticated attacker to modify contents of the intermediate build folder (by default `obj`), aka 'NuGet Package Manager Tampering Vulnerability'.","aliases":["CVE-2019-0976"],"modified":"2024-03-24T20:41:49.187251Z","published":"2022-05-24T22:28:08Z","database_specific":{"cwe_ids":["CWE-732"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-03-24T20:28:51Z","nvd_published_at":"2019-05-16T19:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-0976"},{"type":"WEB","url":"https://github.com/NuGet/Home/issues/7908"},{"type":"WEB","url":"https://github.com/NuGet/NuGet.Client/commit/e32a2ea7096debd3e513188f6779bb1041593326"},{"type":"PACKAGE","url":"https://github.com/NuGet/NuGet.Client"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0976"},{"type":"WEB","url":"https://web.archive.org/web/20200227075944/http://www.securityfocus.com/bid/108210"}],"affected":[{"package":{"name":"NuGet.Commands","ecosystem":"NuGet","purl":"pkg:nuget/NuGet.Commands"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-3hcm-6fjc-47qq/GHSA-3hcm-6fjc-47qq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}