PT-2024-27462 · Microsoft · Nuget Gallery
Jondouglas
·
Published
2024-06-12
·
Updated
2024-06-13
·
CVE-2024-37304
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NuGet Gallery versions prior to 2024.05.28
Description
The NuGet Gallery has a security issue related to its handling of autolinks in Markdown content. It does not adequately sanitize autolinks, allowing attackers to exploit them as a vector for Cross-Site Scripting (XSS) attacks. When a user inputs a Markdown autolink, the link is rendered without proper sanitization, enabling the execution of JavaScript code within the autolink by the browser.
Recommendations
For versions prior to 2024.05.28, update to version 2024.05.28 to resolve the issue. As a temporary workaround, consider disabling the rendering of Markdown autolinks until the patch is applied. Restrict access to user-inputted Markdown content to minimize the risk of exploitation. Avoid using JavaScript code within Markdown autolinks in the affected NuGet Gallery versions until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nuget Gallery