Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4ZjQtMnc0cC1taGpj

Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Permalink: https://github.com/advisories/GHSA-j8f4-2w4p-mhjc
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4ZjQtMnc0cC1taGpj
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 6 years ago
Updated: over 1 year ago


CVSS Score: 5.3
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Identifiers: GHSA-j8f4-2w4p-mhjc, CVE-2017-0256
References: Blast Radius: 7.6

Affected Packages

nuget:Microsoft.AspNetCore.Mvc.WebApiCompatShim
Dependent packages: 40
Dependent repositories: 0
Downloads: 116,960,797 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ViewFeatures
Dependent packages: 539
Dependent repositories: 0
Downloads: 278,907,845 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.TagHelpers
Dependent packages: 106
Dependent repositories: 0
Downloads: 228,814,968 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor
Dependent packages: 151
Dependent repositories: 0
Downloads: 248,368,407 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor.Host
Dependent packages: 2
Dependent repositories: 0
Downloads: 18,682,616 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
nuget:Microsoft.AspNetCore.Mvc.Localization
Dependent packages: 38
Dependent repositories: 0
Downloads: 221,772,760 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Xml
Dependent packages: 33
Dependent repositories: 0
Downloads: 65,702,232 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Json
Dependent packages: 263
Dependent repositories: 0
Downloads: 489,300,441 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.18, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.DataAnnotations
Dependent packages: 84
Dependent repositories: 0
Downloads: 363,063,170 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Cors
Dependent packages: 34
Dependent repositories: 0
Downloads: 221,351,606 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ApiExplorer
Dependent packages: 57
Dependent repositories: 0
Downloads: 327,640,602 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Abstractions
Dependent packages: 783
Dependent repositories: 0
Downloads: 703,771,673 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.37, 2.1.38, 2.2.0
nuget:System.Net.WebSockets.Client
Dependent packages: 82
Dependent repositories: 0
Downloads: 164,479,771 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Net.Security
Dependent packages: 151
Dependent repositories: 0
Downloads: 485,527,906 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Net.Http.WinHttpHandler
Dependent packages: 88
Dependent repositories: 0
Downloads: 110,617,400 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.3.1, 4.3.2, 4.3.3, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 6.0.0, 6.0.1, 7.0.0, 8.0.0, 8.0.1, 8.0.2
nuget:System.Text.Encodings.Web
Dependent packages: 1,161
Dependent repositories: 0
Downloads: 3,003,694,350 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.3.1, 4.4.0, 4.5.0, 4.5.1, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 5.0.1, 6.0.0, 7.0.0, 8.0.0
nuget:System.Net.Http
Dependent packages: 2,306
Dependent repositories: 10
Downloads: 2,272,570,047 total
Affected Version Ranges: = 4.3.1, = 4.1.1
Fixed in: 4.3.2, 4.1.2
All affected versions: 4.1.1, 4.3.1
All unaffected versions: 2.0.20505, 2.0.20710, 4.0.0, 4.1.0, 4.1.2, 4.1.3, 4.1.4, 4.3.0, 4.3.2, 4.3.3, 4.3.4
nuget:Microsoft.AspNetCore.Mvc.Core
Dependent packages: 2,433
Dependent repositories: 0
Downloads: 724,166,838 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.11, 2.1.16, 2.1.34, 2.1.38, 2.2.0, 2.2.2, 2.2.5
nuget:Microsoft.AspNetCore.Mvc
Dependent packages: 1,440
Dependent repositories: 27
Downloads: 220,777,819 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0