Microsoft.AspNetCore.App
Provides a default set of APIs for building an ASP.NET Core application. This package requires the ASP.NET Core runtime. This runtime is installed by the .NET Core SDK, or can be acquired separately using installers available at https://aka.ms/dotnet-download.
Activity
- Latest release
- 4y ago
- Total releases
- 48
- Cadence
- ~27 days
- Last 12 months
- 0
Details
- First release
- Feb 26, 2018
| Version | Released | |
|---|---|---|
2.1.34
patch
|
2.1.34
patch
Dependencies (156)
+ 148 more |
|
2.1.31
patch
|
2.1.31
patch
Dependencies (156)
+ 148 more |
|
2.1.30
patch
|
2.1.30
patch
Dependencies (156)
+ 148 more |
|
2.1.29
patch
|
2.1.29
patch
Dependencies (156)
+ 148 more |
|
2.1.28
patch
|
2.1.28
patch
Dependencies (156)
+ 148 more |
|
2.1.27
patch
|
2.1.27
patch
Dependencies (156)
+ 148 more |
|
2.1.26
patch
|
2.1.26
patch
Dependencies (146)
+ 138 more |
|
2.1.25
patch
|
2.1.25
patch
Dependencies (145)
+ 137 more |
|
2.1.24
patch
|
2.1.24
patch
Dependencies (145)
+ 137 more |
|
2.1.23
patch
|
2.1.23
patch
Dependencies (145)
+ 137 more |
|
2.1.22
patch
|
2.1.22
patch
Dependencies (145)
+ 137 more |
|
2.1.21
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.21
patch
Dependencies (145)
+ 137 more |
|
2.1.20
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.20
patch
Dependencies (145)
+ 137 more |
|
2.1.19
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.19
patch
Dependencies (145)
+ 137 more |
|
2.1.18
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.18
patch
Dependencies (145)
+ 137 more |
|
2.1.17
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.17
patch
Dependencies (145)
+ 137 more |
|
2.1.16
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.16
patch
Dependencies (145)
+ 137 more |
|
2.1.15
patch
2 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev |
2.1.15
patch
Dependencies (145)
+ 137 more |
|
2.1.14
patch
4 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev |
2.1.14
patch
Dependencies (145)
+ 137 more |
|
2.2.8
patch
|
2.2.8
patch
Dependencies (150)
+ 142 more |
|
2.1.13
patch
4 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev |
2.1.13
patch
Dependencies (145)
+ 137 more |
|
2.2.7
patch
|
2.2.7
patch
Dependencies (150)
+ 142 more |
|
2.2.6
patch
|
2.2.6
patch
Dependencies (150)
+ 142 more |
|
2.1.12
patch
4 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev |
2.1.12
patch
Dependencies (145)
+ 137 more |
|
2.1.11
patch
5 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.11
patch
Dependencies (145)
+ 137 more |
|
2.2.5
patch
1 CVE
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.5
patch
Dependencies (150)
+ 142 more |
|
2.1.10
patch
5 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.10
patch
Dependencies (145)
+ 137 more |
|
2.2.4
patch
1 CVE
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.4
patch
Dependencies (150)
+ 142 more |
|
2.2.3
patch
1 CVE
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.3
patch
Dependencies (150)
+ 142 more |
|
2.1.9
patch
5 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.9
patch
Dependencies (145)
+ 137 more |
|
2.2.2
patch
1 CVE
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.2
patch
Dependencies (150)
+ 142 more |
|
2.1.8
patch
5 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.8
patch
Dependencies (145)
+ 137 more |
|
2.2.1
patch
1 CVE
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.2.1
patch
Dependencies (150)
+ 142 more |
|
2.1.7
patch
5 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev |
2.1.7
patch
Dependencies (145)
+ 137 more |
|
2.2.0
minor
2 CVEs
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev |
2.2.0
minor
Dependencies (150)
+ 142 more |
|
2.1.6
patch
6 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev |
2.1.6
patch
Dependencies (145)
+ 137 more |
|
2.2.0-preview3-35497
pre
|
2.2.0-preview3-35497
pre
Dependencies (150)
+ 142 more |
|
2.1.5
patch
6 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev |
2.1.5
patch
Dependencies (145)
+ 137 more |
|
2.2.0-preview2-35157
pre
|
2.2.0-preview2-35157
pre
Dependencies (149)
+ 141 more |
|
2.1.4
patch
6 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev |
2.1.4
patch
Dependencies (145)
+ 137 more |
|
2.2.0-preview1-35029
pre
|
2.2.0-preview1-35029
pre
Dependencies (148)
+ 140 more |
|
2.1.3
patch
7 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2018-8409
GHSA-j378-6mmw-hqfr
Oct 16, 2018
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
Fixed in
2.1.4
References Updated Dec 08, 2024 · Source: OSV.dev |
2.1.3
patch
Dependencies (144)
+ 136 more |
|
2.1.2
patch
7 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2018-8409
GHSA-j378-6mmw-hqfr
Oct 16, 2018
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
Fixed in
2.1.4
References Updated Dec 08, 2024 · Source: OSV.dev |
2.1.2
patch
Dependencies (144)
+ 136 more |
|
2.1.1
patch
8 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
GHSA-cgpw-2gph-2r9g
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, and Microsoft.AspNetCore.Server.Kestrel.Core
Medium
Microsoft is aware of a denial of service vulnerability in ASP.NET Core when a malformed request is terminated. An attacker who successfully exploited this vulnerability could cause a denial of service attack. The update addresses the vulnerability by correcting how ASP.NET Core handles such requests. Affected versions
2.1.0
2.1.1
Fixed in
2.1.2
References Updated Dec 02, 2024 · Source: OSV.dev
CVE-2018-8409
GHSA-j378-6mmw-hqfr
Oct 16, 2018
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
Fixed in
2.1.4
References Updated Dec 08, 2024 · Source: OSV.dev |
2.1.1
patch
Dependencies (144)
+ 136 more |
|
2.1.0
initial
8 CVEs
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1597
GHSA-f8qx-mjcq-wfgx
BIT-aspnet-core-2020-1597
May 24, 2022
ASP.NET Core Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 9 more Show less
2.1.2
2.1.20
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.21
References
Updated Feb 18, 2024 · Source: OSV.dev
CVE-2020-0603
GHSA-655q-9gvg-q4cm
BIT-aspnet-core-2020-0603
May 24, 2022
Remote code execution in ASP.NET Core
High
A remote code execution vulnerability exists in ASP.NET Core software when the software fails to handle objects in memory.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka 'ASP.NET Core Remote Code Execution Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2020-0602
GHSA-23cv-jh4v-vffm
BIT-aspnet-core-2020-0602
May 24, 2022
Denial of service in ASP.NET Core
Medium
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'. Affected versions
3.1.0
3.0.0
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.2
2.1.3
2.1.4
+ 5 more Show less
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.15
3.0.1
3.1.1
References
Updated Nov 28, 2024 · Source: OSV.dev
CVE-2019-1075
GHSA-prrf-397v-83xh
May 24, 2022
Open redirect in ASP.NET Core
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect, aka 'ASP.NET Core Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.1.0
2.1.1
2.1.10
2.1.11
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.12
2.2.6
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
GHSA-cgpw-2gph-2r9g
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.All, Microsoft.AspNetCore.App, and Microsoft.AspNetCore.Server.Kestrel.Core
Medium
Microsoft is aware of a denial of service vulnerability in ASP.NET Core when a malformed request is terminated. An attacker who successfully exploited this vulnerability could cause a denial of service attack. The update addresses the vulnerability by correcting how ASP.NET Core handles such requests. Affected versions
2.1.0
2.1.1
Fixed in
2.1.2
References Updated Dec 02, 2024 · Source: OSV.dev
CVE-2018-8409
GHSA-j378-6mmw-hqfr
Oct 16, 2018
Denial of service vulnerability exists when System.IO.Pipelines improperly handles requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
Fixed in
2.1.4
References Updated Dec 08, 2024 · Source: OSV.dev |
2.1.0
initial
Dependencies (144)
+ 136 more |
|
2.1.0-rc1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-rc1-final
pre
Dependencies (144)
+ 136 more |
|
2.1.0-preview2-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-preview2-final
pre
Dependencies (143)
+ 135 more |
|
2.1.0-preview1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
+ 13 more Show less
2.1.17
2.1.18
2.1.19
2.1.2
2.1.20
2.1.21
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-preview1-final
pre
Dependencies (142)
+ 134 more |