Описание
ASP.NET Core Denial of Service Vulnerability
A flaw was found in dotnet. The way client disconnects are handled can allow a remote, unauthenticated attacker to exploit this vulnerability to cause a denial of service against an ASP.NET Core application. The highest threat from this vulnerability is to system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
.NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21 | Not affected | ||
Red Hat Enterprise Linux 8 | dotnet | Not affected | ||
.NET Core on Red Hat Enterprise Linux | rh-dotnet31-dotnet | Fixed | RHSA-2021:2350 | 09.06.2021 |
.NET Core on Red Hat Enterprise Linux | rh-dotnet50-dotnet | Fixed | RHSA-2021:2351 | 09.06.2021 |
Red Hat Enterprise Linux 8 | dotnet3.1 | Fixed | RHSA-2021:2352 | 09.06.2021 |
Red Hat Enterprise Linux 8 | dotnet5.0 | Fixed | RHSA-2021:2353 | 09.06.2021 |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=1966990dotnet: ASP.NET Core Client Disconnect Denial of Service
EPSS
Процентиль: 89%
0.05149
Низкий
5.9 Medium
CVSS3
EPSS
Процентиль: 89%
0.05149
Низкий
5.9 Medium
CVSS3