MEDIUM6.1
GHSA-prrf-397v-83xh
Open redirect in ASP.NET Core
Quick fix
GHSA-prrf-397v-83xh — Microsoft.AspNetCore.App: upgrade to the fixed version with the command below.
dotnet add package Microsoft.AspNetCore.App --version 2.2.6Details
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Microsoft.AspNetCore.App
Introduced in:
2.2.0Fixed in: 2.2.6Fix
dotnet add package Microsoft.AspNetCore.App --version 2.2.6NuGet/Microsoft.AspNetCore.App
Introduced in:
2.1.0Fixed in: 2.1.12Fix
dotnet add package Microsoft.AspNetCore.App --version 2.1.12NuGet/Microsoft.AspNetCore.All
Introduced in:
2.2.0Fixed in: 2.2.6Fix
dotnet add package Microsoft.AspNetCore.All --version 2.2.6NuGet/Microsoft.AspNetCore.All
Introduced in:
2.1.0Fixed in: 2.1.12Fix
dotnet add package Microsoft.AspNetCore.All --version 2.1.12NuGet/Microsoft.AspNetCore.Server.IIS
Introduced in:
2.2.0Fixed in: 2.2.6Fix
dotnet add package Microsoft.AspNetCore.Server.IIS --version 2.2.6NuGet/Microsoft.AspNetCore.Server.HttpSys
Introduced in:
2.2.0Fixed in: 2.2.6Fix
dotnet add package Microsoft.AspNetCore.Server.HttpSys --version 2.2.6NuGet/Microsoft.AspNetCore.Server.HttpSys
Introduced in:
2.1.0Fixed in: 2.1.12Fix
dotnet add package Microsoft.AspNetCore.Server.HttpSys --version 2.1.12