Microsoft.AspNetCore.Mvc.Core
ASP.NET Core MVC core components. Contains common action result types, attribute routing, application model conventions, API explorer, application parts, filters, formatters, model binding, and more. Commonly used types: Microsoft.AspNetCore.Mvc.AreaAttribute Microsoft.AspNetCore.Mvc.BindAttribute Microsoft.AspNetCore.Mvc.ControllerBase Microsoft.AspNetCore.Mvc.FromBodyAttribute Microsoft.AspNetCore.Mvc.FromFormAttribute Microsoft.AspNetCore.Mvc.RequireHttpsAttribute Microsoft.AspNetCore.Mvc.RouteAttribute
Activity
- Latest release
- 5d ago
- Total releases
- 49
- Cadence
- ~27 days
- Last 12 months
- 6
Details
- First release
- May 16, 2016
| Version | Released | |
|---|---|---|
2.3.13
patch
|
2.3.13
patch
Dependencies (14)
+ 6 more |
|
2.3.12
patch
|
2.3.12
patch
Dependencies (14)
+ 6 more |
|
2.3.11
patch
|
2.3.11
patch
Dependencies (14)
+ 6 more |
|
2.3.10
patch
|
2.3.10
patch
Dependencies (14)
+ 6 more |
|
2.3.9
patch
|
2.3.9
patch
Dependencies (14)
+ 6 more |
|
2.3.8
patch
|
2.3.8
patch
Dependencies (14)
+ 6 more |
|
2.3.0
minor
|
2.3.0
minor
Dependencies (14)
+ 6 more |
|
2.1.38
patch
|
2.1.38
patch
Dependencies (14)
+ 6 more |
|
2.1.34
patch
|
2.1.34
patch
Dependencies (14)
+ 6 more |
|
2.1.16
patch
|
2.1.16
patch
Dependencies (14)
+ 6 more |
|
2.1.11
patch
|
2.1.11
patch
Dependencies (14)
+ 6 more |
|
2.2.5
patch
|
2.2.5
patch
Dependencies (15)
+ 7 more |
|
2.2.2
patch
|
2.2.2
patch
Dependencies (15)
+ 7 more |
|
2.2.0
minor
|
2.2.0
minor
Dependencies (15)
+ 7 more |
|
2.2.0-preview3-35497
pre
|
2.2.0-preview3-35497
pre
Dependencies (15)
+ 7 more |
|
2.1.3
patch
|
2.1.3
patch
Dependencies (14)
+ 6 more |
|
2.2.0-preview2-35157
pre
|
2.2.0-preview2-35157
pre
Dependencies (15)
+ 7 more |
|
2.2.0-preview1-35029
pre
|
2.2.0-preview1-35029
pre
Dependencies (15)
+ 7 more |
|
2.1.2
patch
|
2.1.2
patch
Dependencies (14)
+ 6 more |
|
1.1.8
patch
|
1.1.8
patch
Dependencies (13)
+ 5 more |
|
2.1.1
patch
|
2.1.1
patch
Dependencies (14)
+ 6 more |
|
2.1.0
minor
|
2.1.0
minor
Dependencies (14)
+ 6 more |
|
2.0.4
patch
|
2.0.4
patch
Dependencies (12)
+ 4 more |
|
2.1.0-rc1-final
pre
|
2.1.0-rc1-final
pre
Dependencies (14)
+ 6 more |
|
2.1.0-preview2-final
pre
|
2.1.0-preview2-final
pre
Dependencies (14)
+ 6 more |
|
2.0.3
patch
|
2.0.3
patch
Dependencies (12)
+ 4 more |
|
1.1.7
patch
|
1.1.7
patch
Dependencies (13)
+ 5 more |
|
2.1.0-preview1-final
pre
|
2.1.0-preview1-final
pre
Dependencies (14)
+ 6 more |
|
2.0.2
patch
|
2.0.2
patch
Dependencies (12)
+ 4 more |
|
1.1.6
patch
|
1.1.6
patch
Dependencies (13)
+ 5 more |
|
2.0.1
patch
|
2.0.1
patch
Dependencies (12)
+ 4 more |
|
1.1.5
patch
1 CVE
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev |
1.1.5
patch
Dependencies (13)
+ 5 more |
|
1.0.6
patch
|
1.0.6
patch
Dependencies (12)
+ 4 more |
|
1.1.4
patch
1 CVE
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev |
1.1.4
patch
Dependencies (13)
+ 5 more |
|
1.0.5
patch
1 CVE
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev |
1.0.5
patch
Dependencies (12)
+ 4 more |
|
2.0.0
major
1 CVE
CVE-2017-11879
GHSA-3wcj-rg8q-9cqv
May 14, 2022
Open redirect in ASP.NET Core
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability". Affected versions
2.0.0
Fixed in
2.0.1
References Updated Nov 08, 2023 · Source: OSV.dev |
2.0.0
major
Dependencies (12)
+ 4 more |
|
2.0.0-preview2-final
pre
|
2.0.0-preview2-final
pre
Dependencies (12)
+ 4 more |
|
2.0.0-preview1-final
pre
|
2.0.0-preview1-final
pre
Dependencies (12)
+ 4 more |
|
1.1.3
patch
1 CVE
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev |
1.1.3
patch
Dependencies (13)
+ 5 more |
|
1.0.4
patch
1 CVE
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev |
1.0.4
patch
Dependencies (12)
+ 4 more |
|
1.1.2
patch
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.2
patch
Dependencies (13)
+ 5 more |
|
1.0.3
patch
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.3
patch
Dependencies (12)
+ 4 more |
|
1.1.1
patch
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.1
patch
Dependencies (13)
+ 5 more |
|
1.0.2
patch
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.2
patch
Dependencies (12)
+ 4 more |
|
1.1.0
minor
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.0
minor
Dependencies (13)
+ 5 more |
|
1.1.0-preview1-final
pre
|
1.1.0-preview1-final
pre
Dependencies (12)
+ 4 more |
|
1.0.1
patch
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.1
patch
Dependencies (12)
+ 4 more |
|
1.0.0
initial
5 CVEs
CVE-2017-8700
GHSA-3rp6-rjw4-cq39
May 13, 2022
Cross-origin Resource Sharing bypass in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability". Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
Fixed in
1.0.6
1.1.6
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
Fixed in
1.0.4
1.1.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.0
initial
Dependencies (12)
+ 4 more |
|
1.0.0-rc2-final
pre
|
1.0.0-rc2-final
pre
Dependencies (12)
+ 4 more |