Opentok-.NET-SDK icon indicating copy to clipboard operation
Opentok-.NET-SDK copied to clipboard

nancy.viewengines.razor.1.1.0.nupkg: 1 vulnerabilities (highest severity is: 9.8)

Open mend-for-github-com[bot] opened this issue 3 years ago • 0 comments

Vulnerable Library - nancy.viewengines.razor.1.1.0.nupkg

Path to dependency file: /Samples/Archiving/Archiving.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/nancy/1.1.0/nancy.1.1.0.nupkg

Found in HEAD commit: ffc3b97eddaccb68c64db3a610558e2b423d815d

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in Remediation Available
CVE-2017-9785 High 9.8 nancy.1.1.0.nupkg Transitive N/A

Details

CVE-2017-9785

Vulnerable Library - nancy.1.1.0.nupkg

Nancy is a lightweight web framework for the .Net platform, inspired by Sinatra. Nancy aim at delive...

Library home page: https://api.nuget.org/packages/nancy.1.1.0.nupkg

Path to dependency file: /Samples/Archiving/Archiving.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/nancy/1.1.0/nancy.1.1.0.nupkg

Dependency Hierarchy:

  • nancy.viewengines.razor.1.1.0.nupkg (Root Library)
    • :x: nancy.1.1.0.nupkg (Vulnerable Library)

Found in HEAD commit: ffc3b97eddaccb68c64db3a610558e2b423d815d

Found in base branch: main

Vulnerability Details

Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.

Publish Date: 2017-07-20

URL: CVE-2017-9785

CVSS 3 Score Details (9.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9785

Release Date: 2017-07-20

Fix Resolution: Nancy - 1.4.4,2.0