CVE-2022-30184
published 2022-06-15CVE-2022-30184: .NET and Visual Studio Information Disclosure Vulnerability
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
5.33%
91.7th percentile
.NET and Visual Studio Information Disclosure Vulnerability
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft_visual_studio_2019_version_16.11 | >= 16.11.0 < 16.11.16 | 16.11.16 |
| microsoft | microsoft_visual_studio_2019_version_16.9 | >= 15.0.0 < 16.9.22 | 16.9.22 |
| microsoft | microsoft_visual_studio_2022_version_17.0 | >= 17.0.0 < 17.0.11 | 17.0.11 |
| microsoft | microsoft_visual_studio_2022_version_17.2 | >= 17.2.0 < 17.2.4 | 17.2.4 |
| microsoft | net | — | — |
| microsoft | net_6.0 | >= 6.0.0 < 6.0.6 | 6.0.6 |
| microsoft | net_core | — | — |
| microsoft | net_core_3.1 | >= 3.1 < 3.1.26 | 3.1.26 |
| microsoft | nuget | < 6.2.1 | 6.2.1 |
| microsoft | nuget.exe | >= 6.0.0 < 6.2.0 | 6.2.0 |
| microsoft | visual_studio_2019 | — | — |
| microsoft | visual_studio_2019 | >= 16.0 < 16.9.22 | 16.9.22 |
| microsoft | visual_studio_2019 | >= 16.10 < 16.11.6 | 16.11.6 |
| microsoft | visual_studio_2019_for_mac_version_8.10 | >= 8.1.0 < 17.0.2 | 17.0.2 |
| microsoft | visual_studio_2022 | >= 17.0 < 17.0.4 | 17.0.4 |
| microsoft | visual_studio_2022 | >= 17.0 < 17.0.11 | 17.0.11 |
| microsoft | visual_studio_2022 | >= 17.2 < 17.2.5 | 17.2.5 |
| microsoft | visual_studio_2022_for_mac_version_17.0 | >= 17.0.0 < 17.0.2 | 17.0.2 |
| msrc | microsoft_visual_studio_2019_version_16.11 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.0 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.2 | — | — |
| msrc | net_6.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens PNI
cisa_ics·2023-11-16·CVSS 5.5
[MEDIUM] Siemens PNI
ICS Advisory
##
Siemens PNI
Release DateNovember 16, 2023
Alert CodeICSA-23-320-12
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC PNI
- Vulnerabilities: Improper Input Validation, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to achieve remote code execution, a denial-of-service condi
Red Hat
dotnet: NuGet Credential leak due to loss of control of third party symbol server domain
vendor_redhat·2022-06-14·CVSS 5.5
CVE-2022-30184 [MEDIUM] CWE-212 dotnet: NuGet Credential leak due to loss of control of third party symbol server domain
dotnet: NuGet Credential leak due to loss of control of third party symbol server domain
.NET and Visual Studio Information Disclosure Vulnerability
Microsoft
.NET and Visual Studio Information Disclosure Vulnerability
vendor_msrc·2022-06-14·CVSS 5.5
CVE-2022-30184 [MEDIUM] .NET and Visual Studio Information Disclosure Vulnerability
.NET and Visual Studio Information Disclosure Vulnerability
FAQ: I am using Visual Studio 2019 for Mac version 8.10. Why do the links in the Security Update table point me to the updates for Visual Studio 2022 for Mac?
The .NET 5.0.X SDK that ships within Visual Studio 2019 for Mac is no longer supported, and will no longer receive security updates. The accompanying 3.1.X runtime is still in support, and will continue to receive security updates. See the .NET support policy. Users who wish to remain on Visual Studio 2019 for Mac do so with an understanding that the environment is now only partially secure.
Visual Studio for Mac adheres to the [Microsoft Modern Lifecycle Policy]{https://support.microsoft.com/help/30881}. In accordance with this policy, Visual Studio 2019 for Mac is unsuppo
GHSA
Potential leak of NuGet.org API key
ghsa·2022-06-14
CVE-2022-30184 [MEDIUM] CWE-200 Potential leak of NuGet.org API key
Potential leak of NuGet.org API key
### Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0 and .NET Core 3.1, NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET Core 3.1, and NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0) where a nuget.org api key could leak due to an incorrect comparison with a server url.
### Affected software
#### NuGet & NuGet Packages
- Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat 6.2.0
OSV
Potential leak of NuGet.org API key
osv·2022-06-14
CVE-2022-30184 [MEDIUM] Potential leak of NuGet.org API key
Potential leak of NuGet.org API key
### Description
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0 and .NET Core 3.1, NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0). This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET Core 3.1, and NuGet (NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat version range from 3.5.0 to 6.2.0) where a nuget.org api key could leak due to an incorrect comparison with a server url.
### Affected software
#### NuGet & NuGet Packages
- Any NuGet.exe, NuGet.Commands, NuGet.CommandLine, NuGet.CommandLine.XPlat 6.2.0
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30184https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DMP34G53EA2DBTBLFOAQCDZRRENE2EA2/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XWNH4AC3LFVX35MDRX5OBZDGD2AMH66K/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30184
2022-06-15
Published