Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-1045

Опубликовано: 11 сент. 2020
Источник: debian
EPSS Средний

Описание

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dotnet-core-3.1itppackage

EPSS

Процентиль: 95%
0.20523
Средний

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

CVSS3: 7.5
nvd
больше 5 лет назад

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

CVSS3: 7.5
msrc
больше 5 лет назад

Microsoft ASP.NET Core Security Feature Bypass Vulnerability

CVSS3: 7.5
github
больше 3 лет назад

Cookie parsing failure

oracle-oval
больше 5 лет назад

ELSA-2020-3699: .NET Core 3.1 security and bugfix update (IMPORTANT)

EPSS

Процентиль: 95%
0.20523
Средний