CVE-2024-47604

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 1, 2024
Updated: Nov 13, 2024
CWE ID 79

Summary

CVE-2024-47604 is a newly identified vulnerability affecting NuGet Gallery, a package repository utilized by nuget.org. This issue stems from the NuGetGallery's flawed handling of HTML element attributes, enabling attackers to inject arbitrary HTML or JavaScript code into a victim's browser. exploitation of this vulnerability could potentially lead to significant security risks, including data theft, unauthorized access, or malware installation. Users are advised to implement security measures, such as browser updates and content security policies, to mitigate potential threats. The NuGet team is encouraged to release a patch as soon as possible to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share