Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS0zODg1LThncWMtM3dwZs4AArjp

Potential leak of NuGet.org API key

Description

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0 and .NET Core 3.1, NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A vulnerability exists in .NET 6.0, .NET Core 3.1, and NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0) where a nuget.org api key could leak due to an incorrect comparison with a server url.

Affected software

NuGet & NuGet Packages

.NET SDK(s)

Patches

.NET 6.0 and .NET Core 3.1 updates are also available from Microsoft Update. To access this either type "Check for updates" in your Windows search, or open Settings, choose Update & Security and then click Check for Updates.

Other Details

Announcement for this issue can be found at https://github.com/NuGet/Announcements/issues/62

MSRC details for this can be found at https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30184

Permalink: https://github.com/advisories/GHSA-3885-8gqc-3wpf
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zODg1LThncWMtM3dwZs4AArjp
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: 8 months ago


CVSS Score: 5.5
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Identifiers: GHSA-3885-8gqc-3wpf, CVE-2022-30184
References: Repository: https://github.com/NuGet/NuGet.Client
Blast Radius: 1.0

Affected Packages

nuget:NuGet.CommandLine.XPlat
Dependent packages: 1
Dependent repositories: 0
Downloads: 286,123 total
Affected Version Ranges: >= 6.1.0, < 6.2.1, >= 6.0.0, < 6.0.2, >= 5.10.0, < 5.11.2, >= 5.8.0, < 5.9.2, >= 5.3.0, < 5.7.2, >= 5.0.0, < 5.2.1, >= 3.5.0, < 4.9.5
Fixed in: 6.2.1, 6.0.2, 5.11.2, 5.9.2, 5.7.2, 5.2.1, 4.9.5
All affected versions: 3.5.0, 4.1.0, 4.2.0, 4.3.0, 4.3.1, 4.4.0, 4.5.0, 4.6.0, 4.6.1, 4.6.2, 4.6.3, 4.6.4, 5.7.1, 5.9.0, 5.9.1, 5.10.0, 5.11.0, 6.0.0, 6.1.0, 6.2.0
All unaffected versions: 3.3.0, 3.4.3, 5.7.2, 5.9.2, 5.9.3, 5.11.2, 5.11.3, 5.11.5, 5.11.6, 6.0.2, 6.0.5, 6.0.6, 6.2.1, 6.2.2, 6.2.4, 6.3.0, 6.3.1, 6.3.3, 6.3.4, 6.4.0, 6.4.2, 6.4.3, 6.5.0, 6.5.1, 6.6.0, 6.6.1, 6.6.2, 6.7.0, 6.7.1, 6.8.0, 6.8.1
nuget:NuGet.CommandLine
Dependent packages: 47
Dependent repositories: 0
Downloads: 231,196,893 total
Affected Version Ranges: >= 6.1.0, < 6.2.1, >= 6.0.0, < 6.0.2, >= 5.10.0, < 5.11.2, >= 5.8.0, < 5.9.2, >= 5.3.0, < 5.7.2, >= 5.0.0, < 5.2.1, >= 3.5.0, < 4.9.5
Fixed in: 6.2.1, 6.0.2, 5.11.2, 5.9.2, 5.7.2, 5.2.1, 4.9.5
All affected versions: 3.5.0, 4.1.0, 4.3.0, 4.3.1, 4.4.1, 4.5.0, 4.5.1, 4.6.2, 4.6.3, 4.6.4, 4.7.1, 4.7.2, 4.7.3, 4.8.2, 4.9.2, 4.9.3, 4.9.4, 5.0.2, 5.1.0, 5.2.0, 5.3.0, 5.3.1, 5.4.0, 5.5.1, 5.6.0, 5.7.0, 5.7.1, 5.8.0, 5.8.1, 5.9.1, 5.10.0, 5.11.0, 6.0.0, 6.1.0, 6.2.0
All unaffected versions: 1.6.0, 1.7.0, 1.8.0, 1.8.1, 1.8.4, 1.8.40000, 1.8.40001, 1.8.40002, 2.0.0, 2.0.40000, 2.0.40001, 2.1.0, 2.1.1, 2.1.2, 2.2.0, 2.2.1, 2.5.0, 2.6.0, 2.6.1, 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.8.0, 2.8.1, 2.8.2, 2.8.3, 2.8.5, 2.8.6, 2.12.0, 3.3.0, 3.4.3, 4.9.5, 4.9.6, 5.2.1, 5.7.2, 5.9.2, 5.9.3, 5.11.2, 5.11.3, 5.11.5, 5.11.6, 6.0.2, 6.0.5, 6.0.6, 6.2.1, 6.2.2, 6.2.4, 6.3.0, 6.3.1, 6.3.3, 6.3.4, 6.4.0, 6.4.2, 6.4.3, 6.5.0, 6.5.1, 6.6.1, 6.6.2, 6.7.0, 6.7.1, 6.8.0, 6.8.1, 6.9.1, 6.10.0, 6.10.1, 6.10.2, 6.11.0, 6.11.1, 6.12.0, 6.12.1
nuget:NuGet.Commands
Dependent packages: 26
Dependent repositories: 0
Downloads: 3,927,816 total
Affected Version Ranges: >= 6.1.0, < 6.2.1, >= 6.0.0, < 6.0.2, >= 5.10.0, < 5.11.2, >= 5.8.0, < 5.9.2, >= 5.3.0, < 5.7.2, >= 5.0.0, < 5.2.1, >= 3.5.0, < 4.9.5
Fixed in: 6.2.1, 6.0.2, 5.11.2, 5.9.2, 5.7.2, 5.2.1, 4.9.5
All affected versions: 3.5.0, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.3.1, 4.4.0, 4.5.0, 4.6.0, 4.6.1, 4.6.2, 4.6.3, 4.6.4, 5.7.1, 5.9.0, 5.9.1, 5.10.0, 5.11.0, 6.0.0, 6.1.0, 6.2.0
All unaffected versions: 3.2.0, 3.3.0, 3.4.3, 5.7.2, 5.9.2, 5.9.3, 5.11.2, 5.11.3, 5.11.5, 5.11.6, 6.0.2, 6.0.5, 6.0.6, 6.2.1, 6.2.2, 6.2.4, 6.3.0, 6.3.1, 6.3.3, 6.3.4, 6.4.0, 6.4.2, 6.4.3, 6.5.0, 6.5.1, 6.6.0, 6.6.1, 6.6.2, 6.7.0, 6.7.1, 6.8.0, 6.8.1, 6.9.1, 6.10.0, 6.10.1, 6.10.2, 6.11.0, 6.11.1, 6.12.1