Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4aDctNHYydy0zNnE2

ASP.NET Core fails to properly validate web requests

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Permalink: https://github.com/advisories/GHSA-6xh7-4v2w-36q6
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ4aDctNHYydy0zNnE2
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 6 years ago
Updated: almost 2 years ago


CVSS Score: 7.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Identifiers: GHSA-6xh7-4v2w-36q6, CVE-2017-0247
References: Blast Radius: 10.7

Affected Packages

nuget:System.Net.Http.WinHttpHandler
Dependent packages: 88
Dependent repositories: 0
Downloads: 115,965,479 total
Affected Version Ranges: >= 4.3.0, < 4.5.4, = 4.0.0
Fixed in: 4.5.4, 4.0.1
All affected versions: 4.0.0, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.5.3
All unaffected versions: 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.5.4, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 6.0.0, 6.0.1, 7.0.0, 8.0.0, 8.0.1, 8.0.2, 9.0.0
nuget:Microsoft.AspNetCore.Mvc.WebApiCompatShim
Dependent packages: 40
Dependent repositories: 0
Downloads: 124,451,699 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ViewFeatures
Dependent packages: 539
Dependent repositories: 0
Downloads: 287,914,914 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.TagHelpers
Dependent packages: 106
Dependent repositories: 0
Downloads: 235,652,861 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor
Dependent packages: 151
Dependent repositories: 0
Downloads: 255,861,624 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor.Host
Dependent packages: 2
Dependent repositories: 0
Downloads: 19,024,080 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
nuget:Microsoft.AspNetCore.Mvc.Localization
Dependent packages: 38
Dependent repositories: 0
Downloads: 228,692,810 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Xml
Dependent packages: 33
Dependent repositories: 0
Downloads: 66,795,739 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Json
Dependent packages: 263
Dependent repositories: 0
Downloads: 506,417,764 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.18, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.DataAnnotations
Dependent packages: 84
Dependent repositories: 0
Downloads: 373,054,638 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Cors
Dependent packages: 34
Dependent repositories: 0
Downloads: 227,887,234 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ApiExplorer
Dependent packages: 57
Dependent repositories: 0
Downloads: 335,825,442 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Abstractions
Dependent packages: 783
Dependent repositories: 0
Downloads: 732,658,630 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.37, 2.1.38, 2.2.0
nuget:System.Net.WebSockets.Client
Dependent packages: 82
Dependent repositories: 0
Downloads: 171,142,133 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Net.Security
Dependent packages: 151
Dependent repositories: 0
Downloads: 499,817,970 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Text.Encodings.Web
Dependent packages: 1,161
Dependent repositories: 0
Downloads: 3,262,413,276 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.3.1, 4.4.0, 4.5.0, 4.5.1, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 5.0.1, 6.0.0, 6.0.1, 7.0.0, 8.0.0, 9.0.0
nuget:System.Net.Http
Dependent packages: 2,306
Dependent repositories: 10
Downloads: 2,394,977,490 total
Affected Version Ranges: = 4.3.1, = 4.1.1
Fixed in: 4.3.2, 4.1.2
All affected versions: 4.1.1, 4.3.1
All unaffected versions: 2.0.20505, 2.0.20710, 4.0.0, 4.1.0, 4.1.2, 4.1.3, 4.1.4, 4.3.0, 4.3.2, 4.3.3, 4.3.4
nuget:Microsoft.AspNetCore.Mvc.Core
Dependent packages: 2,433
Dependent repositories: 0
Downloads: 758,852,912 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.11, 2.1.16, 2.1.34, 2.1.38, 2.2.0, 2.2.2, 2.2.5
nuget:Microsoft.AspNetCore.Mvc
Dependent packages: 1,440
Dependent repositories: 27
Downloads: 227,420,730 total
Affected Version Ranges: >= 1.0.0, < 1.0.4, >= 1.1.0, < 1.1.3
Fixed in: 1.0.4, 1.1.3
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0