Microsoft.AspNetCore.Mvc
ASP.NET Core MVC is a web framework that gives you a powerful, patterns-based way to build dynamic websites and web APIs. ASP.NET Core MVC enables a clean separation of concerns and gives you full control over markup.
Activity
- Latest release
- 5d ago
- Total releases
- 43
- Cadence
- ~27 days
- Last 12 months
- 6
Details
- First release
- May 16, 2016
| Version | Released | |
|---|---|---|
2.3.13
patch
|
2.3.13
patch
Dependencies (13)
+ 5 more |
|
2.3.12
patch
|
2.3.12
patch
Dependencies (13)
+ 5 more |
|
2.3.11
patch
|
2.3.11
patch
Dependencies (12)
+ 4 more |
|
2.3.10
patch
|
2.3.10
patch
Dependencies (12)
+ 4 more |
|
2.3.9
patch
|
2.3.9
patch
Dependencies (12)
+ 4 more |
|
2.3.8
patch
|
2.3.8
patch
Dependencies (12)
+ 4 more |
|
2.3.0
minor
|
2.3.0
minor
Dependencies (12)
+ 4 more |
|
2.2.0
minor
|
2.2.0
minor
Dependencies (13)
+ 5 more |
|
2.2.0-preview3-35497
pre
|
2.2.0-preview3-35497
pre
Dependencies (13)
+ 5 more |
|
2.1.3
patch
|
2.1.3
patch
Dependencies (12)
+ 4 more |
|
2.2.0-preview2-35157
pre
|
2.2.0-preview2-35157
pre
Dependencies (13)
+ 5 more |
|
2.2.0-preview1-35029
pre
|
2.2.0-preview1-35029
pre
Dependencies (13)
+ 5 more |
|
2.1.2
patch
|
2.1.2
patch
Dependencies (12)
+ 4 more |
|
1.1.8
patch
|
1.1.8
patch
Dependencies (11)
+ 3 more |
|
2.1.1
patch
|
2.1.1
patch
Dependencies (12)
+ 4 more |
|
2.1.0
minor
|
2.1.0
minor
Dependencies (12)
+ 4 more |
|
2.0.4
patch
|
2.0.4
patch
Dependencies (10)
+ 2 more |
|
2.1.0-rc1-final
pre
|
2.1.0-rc1-final
pre
Dependencies (12)
+ 4 more |
|
2.1.0-preview2-final
pre
|
2.1.0-preview2-final
pre
Dependencies (12)
+ 4 more |
|
2.0.3
patch
|
2.0.3
patch
Dependencies (10)
+ 2 more |
|
1.1.7
patch
|
1.1.7
patch
Dependencies (11)
+ 3 more |
|
2.1.0-preview1-final
pre
|
2.1.0-preview1-final
pre
Dependencies (11)
+ 3 more |
|
2.0.2
patch
|
2.0.2
patch
Dependencies (10)
+ 2 more |
|
1.1.6
patch
|
1.1.6
patch
Dependencies (11)
+ 3 more |
|
2.0.1
patch
|
2.0.1
patch
Dependencies (10)
+ 2 more |
|
1.1.5
patch
|
1.1.5
patch
Dependencies (11)
+ 3 more |
|
1.0.6
patch
|
1.0.6
patch
Dependencies (10)
+ 2 more |
|
1.1.4
patch
|
1.1.4
patch
Dependencies (11)
+ 3 more |
|
1.0.5
patch
|
1.0.5
patch
Dependencies (10)
+ 2 more |
|
2.0.0
major
|
2.0.0
major
Dependencies (10)
+ 2 more |
|
2.0.0-preview2-final
pre
|
2.0.0-preview2-final
pre
Dependencies (10)
+ 2 more |
|
2.0.0-preview1-final
pre
|
2.0.0-preview1-final
pre
Dependencies (10)
+ 2 more |
|
1.1.3
patch
|
1.1.3
patch
Dependencies (11)
+ 3 more |
|
1.0.4
patch
|
1.0.4
patch
Dependencies (10)
+ 2 more |
|
1.1.2
patch
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.2
patch
Dependencies (11)
+ 3 more |
|
1.0.3
patch
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.3
patch
Dependencies (10)
+ 2 more |
|
1.1.1
patch
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.1
patch
Dependencies (11)
+ 3 more |
|
1.0.2
patch
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.2
patch
Dependencies (10)
+ 2 more |
|
1.1.0
minor
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
minor
Dependencies (11)
+ 3 more |
|
1.1.0-preview1-final
pre
|
1.1.0-preview1-final
pre
Dependencies (11)
+ 3 more |
|
1.0.1
patch
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1
patch
Dependencies (10)
+ 2 more |
|
1.0.0
initial
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
initial
Dependencies (10)
+ 2 more |
|
1.0.0-rc2-final
pre
|
1.0.0-rc2-final
pre
Dependencies (10)
+ 2 more |