Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-1045

Опубликовано: 08 сент. 2020
Источник: msrc
CVSS3: 7.5
EPSS Средний

Описание

Microsoft ASP.NET Core Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.

The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.

The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.

Обновления

ПродуктСтатьяОбновление
ASP.NET Core 2.1
ASP.NET Core 3.1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 95%
0.20523
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 5 лет назад

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

CVSS3: 7.5
nvd
больше 5 лет назад

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

CVSS3: 7.5
debian
больше 5 лет назад

<p>A security feature bypass vulnerability exists in the way Microsoft ...

CVSS3: 7.5
github
больше 3 лет назад

Cookie parsing failure

oracle-oval
больше 5 лет назад

ELSA-2020-3699: .NET Core 3.1 security and bugfix update (IMPORTANT)

EPSS

Процентиль: 95%
0.20523
Средний

7.5 High

CVSS3