HIGH7.5
GHSA-hxrm-9w7p-39cc
Cookie parsing failure
Quick fix
GHSA-hxrm-9w7p-39cc — Microsoft.AspNetCore.Http: upgrade to the fixed version with the command below.
dotnet add package Microsoft.AspNetCore.Http --version 2.1.22Details
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Microsoft.AspNetCore.Http
Introduced in:
0Fixed in: 2.1.22Fix
dotnet add package Microsoft.AspNetCore.Http --version 2.1.22NuGet/Microsoft.AspNetCore.App
Introduced in:
0Fixed in: 2.1.22Fix
dotnet add package Microsoft.AspNetCore.App --version 2.1.22NuGet/Microsoft.Owin
Introduced in:
0Fixed in: 4.1.1Fix
dotnet add package Microsoft.Owin --version 4.1.1NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-arm --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-arm64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-x64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-musl-x64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.linux-x64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-x64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.osx-x64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.osx-x64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.win-arm
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-arm --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.win-x64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-x64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.win-x86
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-x86 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64
Introduced in:
3.1.0Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 --version 3.1.8NuGet/Microsoft.AspNetCore.App.Runtime.win-arm64
Introduced in:
3.1.5Fixed in: 3.1.8Fix
dotnet add package Microsoft.AspNetCore.App.Runtime.win-arm64 --version 3.1.8References
- https://nvd.nist.gov/vuln/detail/CVE-2020-1045[ADVISORY]
- https://github.com/dotnet/announcements/issues/165[WEB]
- https://github.com/dotnet/aspnetcore/issues/25701[WEB]
- https://github.com/dotnet/aspnetcore/issues/25701#issuecomment-689434477[WEB]
- https://github.com/github/advisory-database/issues/302[WEB]
- https://github.com/dotnet/aspnetcore/pull/24264[WEB]
- https://access.redhat.com/errata/RHSA-2020:3699[WEB]
- https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3[WEB]
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045[WEB]
- https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600[WEB]