CVE-2022-30184

Severity
5.5MEDIUM
EPSS
0.6%
top 30.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15

Description

.NET and Visual Studio Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages17 packages

Also affects: Fedora 35, 36

Patches

🔴Vulnerability Details

3
CVEList
.NET and Visual Studio Information Disclosure Vulnerability2022-06-15
GHSA
Potential leak of NuGet.org API key2022-06-14
OSV
Potential leak of NuGet.org API key2022-06-14

📋Vendor Advisories

2
Red Hat
dotnet: NuGet Credential leak due to loss of control of third party symbol server domain2022-06-14
Microsoft
.NET and Visual Studio Information Disclosure Vulnerability2022-06-14
CVE-2022-30184 (MEDIUM CVSS 5.5) | .NET and Visual Studio Information | cvebase.io