System.Net.Security
Provides types, such as System.Net.Security.SslStream, that uses SSL/TLS protocols to provide secure network communication between client and server endpoints. Commonly Used Types: System.Net.Security.SslStream System.Net.Security.ExtendedProtectionPolicy When using NuGet 3.x this package requires at least version 3.4.
Activity
- Latest release
- 8y ago
- Total releases
- 17
- Cadence
- ~37 days
- Last 12 months
- 0
Details
- First release
- Jan 16, 2015
| Version | Released | |
|---|---|---|
4.3.2
patch
|
4.3.2
patch
Dependencies (29)
+ 21 more |
|
4.0.2
patch
|
4.0.2
patch
Dependencies (29)
+ 21 more |
|
4.3.1
patch
|
4.3.1
patch
Dependencies (29)
+ 21 more |
|
4.0.1
patch
|
4.0.1
patch
Dependencies (29)
+ 21 more |
|
4.3.0
minor
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
4.3.0
minor
Dependencies (29)
+ 21 more |
|
4.3.0-preview1-24530-04
pre
|
4.3.0-preview1-24530-04
pre
Dependencies (29)
+ 21 more |
|
4.0.0
initial
4 CVEs
CVE-2017-0248
GHSA-ch6p-4jcm-h8vh
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
Medium
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability." Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2017-0247
GHSA-6xh7-4v2w-36q6
Oct 16, 2018
ASP.NET Core fails to properly validate web requests
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
High
None
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range. Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0256
GHSA-j8f4-2w4p-mhjc
Oct 16, 2018
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
None
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Nov 08, 2023 · Source: OSV.dev
CVE-2017-0249
GHSA-qhqf-ghgh-x2m4
Oct 16, 2018
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
7.3
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
Low
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249 Affected versions
4.0.0
4.3.0
Fixed in
4.0.1
4.3.1
References Updated Nov 08, 2023 · Source: OSV.dev |
4.0.0
initial
Dependencies (29)
+ 21 more |
|
4.0.0-rc2-24027
pre
|
4.0.0-rc2-24027
pre
Dependencies (26)
+ 18 more |
|
4.0.0-beta-23516
pre
|
4.0.0-beta-23516
pre
Dependencies (5)
|
|
4.0.0-beta-23409
pre
|
4.0.0-beta-23409
pre
Dependencies (5)
|
|
4.0.0-beta-23225
pre
|
4.0.0-beta-23225
pre
Dependencies (6)
|
|
4.0.0-beta-23123
pre
|
4.0.0-beta-23123
pre
Dependencies (6)
|
|
4.0.0-beta-23109
pre
|
4.0.0-beta-23109
pre
Dependencies (6)
|
|
4.0.0-beta-23019
pre
|
4.0.0-beta-23019
pre
Dependencies (6)
|
|
4.0.0-beta-22816
pre
|
4.0.0-beta-22816
pre
Dependencies (5)
|
|
4.0.0-beta-22605
pre
|
4.0.0-beta-22605
pre
Dependencies (5)
|
|
4.0.0-beta-22416
pre
|
4.0.0-beta-22416
pre
Dependencies (5)
|