Description
CVE-2024-38081 - High Severity Vulnerability
Vulnerable Library - microsoft.net.sdk.webassembly.pack.8.0.4.nupkg
SDK for building and publishing WebAssembly applications.
Library home page: https://api.nuget.org/packages/microsoft.net.sdk.webassembly.pack.8.0.4.nupkg
Path to dependency file: /src/Client/BlazorBoilerplate.Client/BlazorBoilerplate.Client.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.net.sdk.webassembly.pack/8.0.4/microsoft.net.sdk.webassembly.pack.8.0.4.nupkg
Dependency Hierarchy:
- ❌ microsoft.net.sdk.webassembly.pack.8.0.4.nupkg (Vulnerable Library)
Found in HEAD commit: fb0edc2b05ad3543ffd7d76d1793f1f969f2d07c
Found in base branch: master
Vulnerability Details
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Publish Date: 2024-07-09
URL: CVE-2024-38081
CVSS 3 Score Details (7.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-hq7w-xv5x-g34j
Release Date: 2024-07-09
Fix Resolution: Microsoft.IO.Redist - 6.0.1
Step up your Open Source Security Game with Mend here
Activity