CVE-2023-29337
Summary
NuGet Client Remote Code Execution Vulnerability in NuGet.CommandLine in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Commands in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Common in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.PackageManagement in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Protocol in versions 4.7.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, and Microsoft.Build.NuGetSdkResolver in versions 5.9.0-rc.7122, 5.10.0-rc.7240, and 5.11.0-rc.10
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- REQUIRED
- LOW
- HIGH
- HIGH
References
Advisory Timeline
- Published