CVE-2020-1340 is a spoofing vulnerability affecting Microsoft NuGetGallery, stemming from improper sanitization of package metadata input. Rated Medium severity (CVSS 5.4), it requires user interaction and low privileges, allowing an attacker to potentially inject malicious content, leading to limited confidentiality and integrity impacts. While no active exploitation or public exploit code is reported, the vulnerability has received minimal community discussion and media coverage, indicating low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2020.06.09CPE matchmatch criteria | cpe:2.3:a:microsoft:nugetgallery:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.