Inedo ProGet through 2024.22 allows remote attackers to...
High severity
Unreviewed
Published
May 4, 2025
to the GitHub Advisory Database
•
Updated May 4, 2025
Description
Published by the National Vulnerability Database
May 3, 2025
Published to the GitHub Advisory Database
May 4, 2025
Last updated
May 4, 2025
Inedo ProGet through 2024.22 allows remote attackers to reach restricted functionality through the C# reflection layer, as demonstrated by causing a denial of service (when an attacker executes a loop calling RestartWeb) or obtaining potentially sensitive information. Exploitation can occur if Anonymous access is enabled, or if there is a successful CSRF attack.
References