Описание
Denial of service in ASP.NET Core
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-8269
- https://github.com/aspnet/Announcements/issues/385
- https://github.com/github/advisory-database/issues/302
- https://github.com/advisories/GHSA-mv2r-q4g5-j8q5
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8269
- https://www.exploit-db.com/exploits/46101
Пакеты
Microsoft.Data.OData
< 5.8.4
5.8.4
Microsoft.AspNetCore.DataProtection.AzureStorage
>= 2.1.0, < 2.1.13
2.1.13
Microsoft.AspNetCore.DataProtection.AzureStorage
>= 2.2.0, < 2.2.7
2.2.7
Microsoft.AspNetCore.All
>= 2.1.0, < 2.1.13
2.1.13
Microsoft.AspNetCore.All
>= 2.2.0, < 2.2.7
2.2.7
Связанные уязвимости
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.
Уязвимость библиотеки OData, связанная с ошибками обработки запросов, позволяющая нарушителю вызвать отказ в обслуживании