PT-2022-7017 · Microsoft+7 · Net Core 3.1+9

Edward Thomson

·

Published

2022-10-11

·

Updated

2025-01-02

·

CVE-2022-41032

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions
  • NuGet versions 6.3.0 and earlier
  • NuGet versions 6.2.1 and earlier
  • NuGet versions 6.0.2 and earlier
  • NuGet versions 5.11.2 and earlier
  • NuGet versions 5.9.2 and earlier
  • NuGet versions 5.7.2 and earlier
  • NuGet versions 4.9.5 and earlier
  • .NET 6.0 versions prior to 6.0.10
  • .NET Core 3.1 versions prior to 3.1.30
Description A vulnerability exists in .NET and NuGet clients where a malicious actor could cause a user to execute arbitrary code. This issue is related to insufficient access control.
Recommendations
  • If you're using NuGet.exe 6.3.0 or lower, download and install 6.3.1.
  • If you're using NuGet.exe 6.2.1 or lower, download and install 6.2.2.
  • If you're using NuGet.exe 6.0.2 or lower, download and install 6.0.3.
  • If you're using NuGet.exe 5.11.2 or lower, download and install 5.11.3.
  • If you're using NuGet.exe 5.9.2 or lower, download and install 5.9.3.
  • If you're using NuGet.exe 5.7.2 or lower, download and install 5.7.3.
  • If you're using NuGet.exe 4.9.5 or lower, download and install 4.9.6.
  • If you're using .NET Core 6.0, download and install Runtime 6.0.10 or SDK 6.0.110.
  • If you're using .NET Core 3.1, download and install Runtime 3.1.30 or SDK 3.1.424.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6911
ALSA-2022:6912
ALSA-2022:6913
ALSA-2022:7826
ALSA-2022:8434
ALT-PU-2022-3423
ALT-PU-2022-3424
ALT-PU-2023-1305
ALT-PU-2023-1306
ALT-PU-2023-1418
ALT-PU-2023-1419
ALT-PU-2023-1466
ALT-PU-2023-1467
BDU:2023-06453
BIT-DOTNET-2022-41032
BIT-DOTNET-SDK-2022-41032
CESA-2022_6911
CESA-2022_6912
CESA-2022_7826
CVE-2022-41032
GHSA-G3Q9-XF95-8HP5
RHSA-2022:6911
RHSA-2022:6912
RHSA-2022:6913
RHSA-2022:6914
RHSA-2022:6915
RHSA-2022:7826
RHSA-2022:8434
RHSA-2022_6911
RHSA-2022_6912
RHSA-2022_6913
RHSA-2022_7826
RHSA-2022_8434
RLSA-2022:6911
RLSA-2022:6912
RLSA-2022:6913
USN-5670-1

Affected Products

Net 6.0
Net Core 3.1
Alt Linux
Almalinux
Centos
Linuxmint
Nuget
Red Hat
Rocky Linux
Ubuntu