Skip to main content

CVE-2023-29337

Severity High
Score 7.1/10

Summary

NuGet Client Remote Code Execution Vulnerability in NuGet.CommandLine in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Commands in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Common in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.PackageManagement in versions 4.6.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, NuGet.Protocol in versions 4.7.0 before 6.0.5, 6.2.0 before 6.2.4, 6.3.0 before 6.3.3, 6.4.0 before 6.4.2, 6.5.0 before 6.5.1, 6.6.0 before 6.6.1, and Microsoft.Build.NuGetSdkResolver in versions 5.9.0-rc.7122, 5.10.0-rc.7240, and 5.11.0-rc.10

  • HIGH
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • LOW
  • HIGH
  • HIGH

References

Advisory Timeline

  • Published