CVE-2024-47604
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-47604 is a newly identified vulnerability affecting NuGet Gallery, a package repository utilized by nuget.org. This issue stems from the NuGetGallery's flawed handling of HTML element attributes, enabling attackers to inject arbitrary HTML or JavaScript code into a victim's browser. exploitation of this vulnerability could potentially lead to significant security risks, including data theft, unauthorized access, or malware installation. Users are advised to implement security measures, such as browser updates and content security policies, to mitigate potential threats. The NuGet team is encouraged to release a patch as soon as possible to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Gallery
Affected Vendors
- Gallery