HIGH 7.5
GHSA-f8qx-mjcq-wfgx
ASP.NET Core Denial of Service Vulnerability
Details
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka `ASP.NET Core Denial of Service Vulnerability`.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet / Microsoft.AspNetCore.App
Introduced in:
2.1.0 Fixed in: 2.1.21 Fix
dotnet add package Microsoft.AspNetCore.App --version 2.1.21 NuGet / Microsoft.AspNetCore.All
Introduced in:
2.1.0 Fixed in: 2.1.21 Fix
dotnet add package Microsoft.AspNetCore.All --version 2.1.21 NuGet / Microsoft.AspNetCore.App.Runtime.linux-arm
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-arm --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.linux-arm64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-arm64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.linux-musl-x64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-musl-x64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.linux-x64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-x64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.osx-x64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.osx-x64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.win-arm
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-arm --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.win-arm64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-arm64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.win-x64
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-x64 --version 3.1.7 NuGet / Microsoft.AspNetCore.App.Runtime.win-x86
Introduced in:
3.1.0 Fixed in: 3.1.7 Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-x86 --version 3.1.7 References
- https://nvd.nist.gov/vuln/detail/CVE-2020-1597 [ADVISORY]
- https://github.com/dotnet/announcements/issues/162 [WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT [WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZW4CBI26KSO3PRL3HLVVISXPPOYUHSXO [WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WH5FQ5VT3JGHXFXOETHCTBWJUIAPGHHT [WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZW4CBI26KSO3PRL3HLVVISXPPOYUHSXO [WEB]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1597 [WEB]