CVE-2019-0976 is a tampering vulnerability in the NuGet Package Manager affecting Linux and Mac operating systems. An authenticated attacker could exploit this flaw to modify the contents of the intermediate build folder, potentially leading to unauthorized alterations of project components. With a CVSS score of 5.5 (Medium), it requires local access and low privileges, but its impact is limited to integrity, with no confidentiality or availability compromise. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it received limited media coverage and community discussion at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.2CPE matchmatch criteria | cpe:2.3:a:microsoft:nuget:5.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.