{"id":"GHSA-mx3q-j2g2-5qxq","summary":"Deserialization of Untrusted Data in NancyFX Nancy","details":"Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.","aliases":["CVE-2017-9785"],"modified":"2023-11-08T03:59:29.080535Z","published":"2022-05-17T02:26:07Z","database_specific":{"github_reviewed_at":"2022-06-30T19:51:21Z","nvd_published_at":"2017-07-20T12:29:00Z","cwe_ids":["CWE-502"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-9785"},{"type":"WEB","url":"https://github.com/NancyFx/Nancy/releases/tag/v1.4.4"}],"affected":[{"package":{"name":"Nancy","ecosystem":"NuGet","purl":"pkg:nuget/Nancy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.4"}]}],"versions":["0.10.0","0.11.0","0.12.0","0.12.1","0.13.0","0.14.0","0.14.1","0.15.0","0.15.1","0.15.2","0.15.3","0.16.0","0.16.1","0.17.0","0.17.1","0.18.0","0.20.0","0.21.0","0.21.1","0.22.0","0.22.1","0.22.2","0.23.0","0.23.1","0.23.2","0.4.0","0.5.0","0.6.0","0.7.0","0.7.1","0.8.0","0.8.1","0.9.0","1.0.0","1.1.0","1.2.0","1.3.0","1.4.0","1.4.1","1.4.2","1.4.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mx3q-j2g2-5qxq/GHSA-mx3q-j2g2-5qxq.json","last_known_affected_version_range":"\u003c= 1.4.3"}},{"package":{"name":"Nancy","ecosystem":"NuGet","purl":"pkg:nuget/Nancy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-alpha"},{"fixed":"2.0.0"}]}],"versions":["2.0.0-alpha","2.0.0-barneyrubble","2.0.0-clienteastwood","2.0.0-clinteastwood"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.0.0-clinteastwood","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-mx3q-j2g2-5qxq/GHSA-mx3q-j2g2-5qxq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}