VDB
KO
MEDIUM 6.1

GHSA-prrf-397v-83xh

Open redirect in ASP.NET Core

Details

A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet / Microsoft.AspNetCore.App
Introduced in: 2.2.0 Fixed in: 2.2.6
Fix dotnet add package Microsoft.AspNetCore.App --version 2.2.6
NuGet / Microsoft.AspNetCore.App
Introduced in: 2.1.0 Fixed in: 2.1.12
Fix dotnet add package Microsoft.AspNetCore.App --version 2.1.12
NuGet / Microsoft.AspNetCore.All
Introduced in: 2.2.0 Fixed in: 2.2.6
Fix dotnet add package Microsoft.AspNetCore.All --version 2.2.6
NuGet / Microsoft.AspNetCore.All
Introduced in: 2.1.0 Fixed in: 2.1.12
Fix dotnet add package Microsoft.AspNetCore.All --version 2.1.12
NuGet / Microsoft.AspNetCore.Server.IIS
Introduced in: 2.2.0 Fixed in: 2.2.6
Fix dotnet add package Microsoft.AspNetCore.Server.IIS --version 2.2.6
NuGet / Microsoft.AspNetCore.Server.HttpSys
Introduced in: 2.2.0 Fixed in: 2.2.6
Fix dotnet add package Microsoft.AspNetCore.Server.HttpSys --version 2.2.6
NuGet / Microsoft.AspNetCore.Server.HttpSys
Introduced in: 2.1.0 Fixed in: 2.1.12
Fix dotnet add package Microsoft.AspNetCore.Server.HttpSys --version 2.1.12

References