HIGH 7.5
GHSA-7mfr-774f-w5r9
Improper Certificate Validation
Details
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet / System.Security.Cryptography.X509Certificates
Introduced in:
4.0.0 Fixed in: 4.1.2 Fix
dotnet add package System.Security.Cryptography.X509Certificates --version 4.1.2 NuGet / Microsoft.NETCore.App
Introduced in:
1.0.0 Fixed in: 2.0.3 Fix
dotnet add package Microsoft.NETCore.App --version 2.0.3