CVE Vulnerabilities

CVE-2023-29337

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Jun 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NuGet Client Remote Code Execution Vulnerability

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
NugetMicrosoft6.0.4 (including)6.0.4 (including)
NugetMicrosoft6.2.3 (including)6.2.3 (including)
NugetMicrosoft6.3.2 (including)6.3.2 (including)
NugetMicrosoft6.4.1 (including)6.4.1 (including)
NugetMicrosoft6.5.0 (including)6.5.0 (including)
NugetMicrosoft6.6.0 (including)6.6.0 (including)
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet60-dotnet-0:6.0.118-1.el7_9*
Red Hat Enterprise Linux 8RedHatdotnet6.0-0:6.0.118-1.el8_8*
Red Hat Enterprise Linux 8RedHatdotnet7.0-0:7.0.107-1.el8_8*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatdotnet6.0-0:6.0.120-1.el8_6*
Red Hat Enterprise Linux 9RedHatdotnet6.0-0:6.0.118-1.el9_2*
Red Hat Enterprise Linux 9RedHatdotnet7.0-0:7.0.107-1.el9_2*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatdotnet6.0-0:6.0.120-1.el9_0*
Dotnet6Ubuntudevel*
Dotnet6Ubuntujammy*
Dotnet6Ubuntukinetic*
Dotnet6Ubuntulunar*
Dotnet6Ubuntuupstream*
Dotnet7Ubuntudevel*
Dotnet7Ubuntujammy*
Dotnet7Ubuntukinetic*
Dotnet7Ubuntulunar*
Dotnet7Ubuntuupstream*

Potential Mitigations

References