Back to Database
Status published
High
CVE-2024-47604
XSS vulnerability in NuGetGallery HTML attributes handling
Vulnerability Description
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47604
Credits & Attribution
No credits recorded in the NVD database.
References
Affected Vendor
NuGet
View all reports →Affected Software
NuGetGallery
Vulnerable Versions:
> 2024.06.21, <= 2024.09.25
Timeline
Official Publish:
October 1st, 2024
Last Modified:
October 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N