Описание
.NET and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. The Microsoft Security Advisory describes the issue of a malicious client that can send MyCookie=chunks-2147483647 without the actual cookie chunks, causing large allocations, exceptions, and excess CPU utilization on the server when it tries to read or delete that many chunks.
Отчет
Affected .NET versions: 6.0, 5.0, 3.1.
Дополнительная информация
Статус:
Important
Дефект:
CWE-565
https://bugzilla.redhat.com/show_bug.cgi?id=2083647dotnet: malicious content causes high CPU and memory usage
7.5 High
CVSS3
7.5 High
CVSS3