Microsoft.NETCore.App
A set of .NET APIs that are included in the default .NET Core application model. d01b2fb7bc6bd4911e157fbd51353059a3ba1a6c When using NuGet 3.x this package requires at least version 3.4.
Activity
- Latest release
- 5y ago
- Total releases
- 84
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- First release
- Jun 27, 2016
| Version | Released | |
|---|---|---|
2.1.30
patch
|
2.1.30
patch
Dependencies (47)
+ 39 more |
|
2.1.29
patch
|
2.1.29
patch
Dependencies (47)
+ 39 more |
|
2.1.28
patch
1 CVE
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev |
2.1.28
patch
Dependencies (47)
+ 39 more |
|
2.1.27
patch
1 CVE
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev |
2.1.27
patch
Dependencies (47)
+ 39 more |
|
2.1.26
patch
1 CVE
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev |
2.1.26
patch
Dependencies (47)
+ 39 more |
|
2.1.25
patch
1 CVE
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev |
2.1.25
patch
Dependencies (47)
+ 39 more |
|
2.1.24
patch
2 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev |
2.1.24
patch
Dependencies (47)
+ 39 more |
|
2.1.23
patch
2 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev |
2.1.23
patch
Dependencies (47)
+ 39 more |
|
2.1.22
patch
2 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev |
2.1.22
patch
Dependencies (47)
+ 39 more |
|
2.1.21
patch
2 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev |
2.1.21
patch
Dependencies (47)
+ 39 more |
|
2.1.20
patch
2 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev |
2.1.20
patch
Dependencies (47)
+ 39 more |
|
2.1.19
patch
3 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev |
2.1.19
patch
Dependencies (47)
+ 39 more |
|
2.1.18
patch
3 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev |
2.1.18
patch
Dependencies (47)
+ 39 more |
|
2.1.17
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.17
patch
Dependencies (47)
+ 39 more |
|
2.1.16
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.16
patch
Dependencies (47)
+ 39 more |
|
2.1.15
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.15
patch
Dependencies (47)
+ 39 more |
|
2.1.14
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.14
patch
Dependencies (47)
+ 39 more |
|
2.2.8
patch
|
2.2.8
patch
Dependencies (4)
|
|
2.1.13
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.13
patch
Dependencies (47)
+ 39 more |
|
2.2.7
patch
|
2.2.7
patch
Dependencies (4)
|
|
2.1.12
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.12
patch
Dependencies (47)
+ 39 more |
|
2.2.6
patch
|
2.2.6
patch
Dependencies (4)
|
|
2.1.11
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.11
patch
Dependencies (47)
+ 39 more |
|
1.1.13
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.13
patch
Dependencies (55)
+ 47 more |
|
2.2.5
patch
|
2.2.5
patch
Dependencies (4)
|
|
1.0.16
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.16
patch
Dependencies (47)
+ 39 more |
|
2.1.10
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.10
patch
Dependencies (47)
+ 39 more |
|
2.2.4
patch
|
2.2.4
patch
Dependencies (4)
|
|
2.2.3
patch
|
2.2.3
patch
Dependencies (4)
|
|
1.0.15
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.15
patch
Dependencies (47)
+ 39 more |
|
2.1.9
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.9
patch
Dependencies (47)
+ 39 more |
|
1.1.12
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.12
patch
Dependencies (55)
+ 47 more |
|
1.1.11
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.11
patch
Dependencies (55)
+ 47 more |
|
1.0.14
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.14
patch
Dependencies (47)
+ 39 more |
|
2.2.2
patch
|
2.2.2
patch
Dependencies (4)
|
|
2.1.8
patch
4 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev |
2.1.8
patch
Dependencies (47)
+ 39 more |
|
2.2.1
patch
1 CVE
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.2.1
patch
Dependencies (4)
|
|
2.1.7
patch
5 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.1.7
patch
Dependencies (47)
+ 39 more |
|
2.2.0
minor
3 CVEs
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2019-0545
GHSA-2xjx-v99w-gqf3
May 14, 2022
Exposure of Sensitive Information in System.Net.Http
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
Fixed in
2.1.7
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev |
2.2.0
minor
Dependencies (4)
|
|
2.1.6
patch
8 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2019-0545
GHSA-2xjx-v99w-gqf3
May 14, 2022
Exposure of Sensitive Information in System.Net.Http
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
Fixed in
2.1.7
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8416
GHSA-5633-f33j-c6f7
May 13, 2022
Tampering vulnerability in .NET Core
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References Updated Dec 05, 2024 · Source: OSV.dev |
2.1.6
patch
Dependencies (47)
+ 39 more |
|
2.2.0-preview3-27014-02
pre
|
2.2.0-preview3-27014-02
pre
Dependencies (4)
|
|
1.1.10
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.10
patch
Dependencies (55)
+ 47 more |
|
1.0.13
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.0.13
patch
Dependencies (47)
+ 39 more |
|
2.1.5
patch
8 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2019-0545
GHSA-2xjx-v99w-gqf3
May 14, 2022
Exposure of Sensitive Information in System.Net.Http
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
Fixed in
2.1.7
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8416
GHSA-5633-f33j-c6f7
May 13, 2022
Tampering vulnerability in .NET Core
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References Updated Dec 05, 2024 · Source: OSV.dev |
2.1.5
patch
Dependencies (47)
+ 39 more |
|
2.2.0-preview2-26905-02
pre
|
2.2.0-preview2-26905-02
pre
Dependencies (4)
|
|
2.1.4
patch
8 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2019-0545
GHSA-2xjx-v99w-gqf3
May 14, 2022
Exposure of Sensitive Information in System.Net.Http
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
Fixed in
2.1.7
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8416
GHSA-5633-f33j-c6f7
May 13, 2022
Tampering vulnerability in .NET Core
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References Updated Dec 05, 2024 · Source: OSV.dev |
2.1.4
patch
Dependencies (47)
+ 39 more |
|
2.2.0-preview-26820-02
pre
|
2.2.0-preview-26820-02
pre
Dependencies (4)
|
|
2.1.3
patch
8 CVEs
CVE-2021-34485
GHSA-vgwq-hfqc-58wv
BIT-dotnet-2021-34485
BIT-dotnet-sdk-2021-34485
Oct 20, 2022
.NET Core Information Disclosure Vulnerability
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability. An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 when dumps created by the tool to collect crash dumps and dumps on demand are created with global read permissions on Linux and macOS. Patches
Other Details
Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 17 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.29
References
Updated Dec 06, 2024 · Source: OSV.dev
CVE-2021-1721
GHSA-3gp9-h8hw-pxpw
BIT-dotnet-2021-1721
BIT-dotnet-sdk-2021-1721
May 24, 2022
Denial of service in .NET core
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
.NET Core and Visual Studio Denial of Service Vulnerability due to a vulnerability which exists when creating HTTPS web request during X509 certificate chain building. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 13 more Show less
2.1.2
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.25
References Updated Nov 29, 2024 · Source: OSV.dev
CVE-2020-1147
GHSA-g5vf-38cp-4px9
May 24, 2022
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
+ 8 more Show less
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.20
References
Updated Oct 22, 2025 · Source: OSV.dev
CVE-2020-1108
GHSA-3w5p-jhp5-c29q
BIT-dotnet-2020-1108
BIT-dotnet-sdk-2020-1108
BIT-powershell-2020-1108
May 24, 2022
.NET Core & .NET Framework Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'. Affected versions
2.1.0
2.1.1
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.2
2.1.3
+ 6 more Show less
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
Fixed in
2.1.18
References Updated Sep 04, 2025 · Source: OSV.dev
CVE-2019-0564
GHSA-6px8-22w5-w334
May 14, 2022
Denial of service in ASP.NET Core
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548. Affected versions
2.2.0
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
2.2.1
References
Updated Dec 05, 2024 · Source: OSV.dev
CVE-2019-0545
GHSA-2xjx-v99w-gqf3
May 14, 2022
Exposure of Sensitive Information in System.Net.Http
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
Fixed in
2.1.7
2.2.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2019-0657
GHSA-x5qj-9vmx-7g6g
May 14, 2022
Improper Input Validation in .Net Framework API's
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
High
None
A vulnerability exists in certain .Net Framework API's and Visual Studio in the way they parse URL's, aka '.NET Framework and Visual Studio Spoofing Vulnerability'. Affected versions
2.2.0
2.2.1
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
Fixed in
2.1.8
2.2.2
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2018-8416
GHSA-5633-f33j-c6f7
May 13, 2022
Tampering vulnerability in .NET Core
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1. Affected versions
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
Fixed in
2.1.7
References Updated Dec 05, 2024 · Source: OSV.dev |
2.1.3
patch
Dependencies (47)
+ 39 more |
|
2.0.9
patch
|
2.0.9
patch
Dependencies (55)
+ 47 more |
|
1.1.9
patch
1 CVE
CVE-2017-11770
GHSA-7mfr-774f-w5r9
Apr 12, 2022
Improper Certificate Validation
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability". Affected versions
1.0.0
1.0.1
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.3
1.0.4
1.0.5
+ 21 more Show less
1.0.5-servicing-004880-00
1.0.7
1.0.8
1.0.9
1.1.0
1.1.0-preview1-001100-00
1.1.1
1.1.10
1.1.11
1.1.12
1.1.13
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
2.0.0
2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
Fixed in
2.0.3
References Updated Nov 08, 2023 · Source: OSV.dev |
1.1.9
patch
Dependencies (55)
+ 47 more |