Microsoft.AspNetCore.Http
ASP.NET Core default HTTP feature implementations.
Activity
- Latest release
- 1mo ago
- Total releases
- 34
- Cadence
- ~41 days
- Last 12 months
- 5
Details
- First release
- May 16, 2016
| Version | Released | |
|---|---|---|
2.3.12
patch
|
2.3.12
patch
Dependencies (5)
|
|
2.3.11
patch
|
2.3.11
patch
Dependencies (5)
|
|
2.3.10
patch
|
2.3.10
patch
Dependencies (5)
|
|
2.3.9
patch
|
2.3.9
patch
Dependencies (5)
|
|
2.3.8
patch
|
2.3.8
patch
Dependencies (5)
|
|
2.3.0
minor
|
2.3.0
minor
Dependencies (5)
|
|
2.1.34
patch
|
2.1.34
patch
Dependencies (5)
|
|
2.1.22
patch
|
2.1.22
patch
Dependencies (5)
|
|
2.2.2
patch
|
2.2.2
patch
Dependencies (5)
|
|
2.2.0
minor
|
2.2.0
minor
Dependencies (5)
|
|
2.2.0-preview3-35497
pre
|
2.2.0-preview3-35497
pre
Dependencies (5)
|
|
2.2.0-preview2-35157
pre
|
2.2.0-preview2-35157
pre
Dependencies (5)
|
|
2.2.0-preview1-35029
pre
|
2.2.0-preview1-35029
pre
Dependencies (5)
|
|
2.1.1
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.1
patch
Dependencies (5)
|
|
2.1.0
minor
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0
minor
Dependencies (5)
|
|
2.0.3
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.3
patch
Dependencies (5)
|
|
2.1.0-rc1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-rc1-final
pre
Dependencies (5)
|
|
2.1.0-preview2-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-preview2-final
pre
Dependencies (5)
|
|
2.0.2
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.2
patch
Dependencies (5)
|
|
2.1.0-preview1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.1.0-preview1-final
pre
Dependencies (5)
|
|
2.0.1
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.1
patch
Dependencies (5)
|
|
1.0.4
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.4
patch
Dependencies (7)
|
|
2.0.0
major
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.0
major
Dependencies (5)
|
|
2.0.0-preview2-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.0-preview2-final
pre
Dependencies (5)
|
|
2.0.0-preview1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
2.0.0-preview1-final
pre
Dependencies (6)
|
|
1.1.2
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.1.2
patch
Dependencies (7)
|
|
1.0.3
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.3
patch
Dependencies (7)
|
|
1.1.1
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.1.1
patch
Dependencies (7)
|
|
1.0.2
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.2
patch
Dependencies (7)
|
|
1.0.1
patch
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.1
patch
Dependencies (7)
|
|
1.1.0
minor
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.1.0
minor
Dependencies (7)
|
|
1.1.0-preview1-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.1.0-preview1-final
pre
Dependencies (7)
|
|
1.0.0
initial
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.0
initial
Dependencies (7)
|
|
1.0.0-rc2-final
pre
1 CVE
CVE-2020-1045
GHSA-hxrm-9w7p-39cc
BIT-aspnet-core-2020-1045
May 24, 2022
Cookie parsing failure
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. Affected versions
0.0.1-alpha
1.0.0
1.0.0-rc2-final
1.0.1
1.0.2
1.0.3
1.0.4
1.1.0
1.1.0-preview1-final
1.1.1
1.1.2
2.0.0
+ 10 more Show less
2.0.0-preview1-final
2.0.0-preview2-final
2.0.1
2.0.2
2.0.3
2.1.0
2.1.0-preview1-final
2.1.0-preview2-final
2.1.0-rc1-final
2.1.1
Fixed in
2.1.22
References
Updated Nov 29, 2024 · Source: OSV.dev |
1.0.0-rc2-final
pre
Dependencies (7)
|