VDB
KO
MEDIUM 5.9

GHSA-x5qj-9vmx-7g6g

Improper Input Validation in .Net Framework API's

Details

A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet / Microsoft.NETCore.App
Introduced in: 2.2.0 Fixed in: 2.2.2
Fix dotnet add package Microsoft.NETCore.App --version 2.2.2
NuGet / Microsoft.NETCore.App
Introduced in: 2.1.0 Fixed in: 2.1.8
Fix dotnet add package Microsoft.NETCore.App --version 2.1.8
NuGet / System.Private.Uri
Introduced in: 4.3.0 Fixed in: 4.3.2
Fix dotnet add package System.Private.Uri --version 4.3.2

References