Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFocWYtZ2hnaC14Mm00
High severity vulnerability that affects Microsoft.AspNetCore.Mvc
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249
Permalink: https://github.com/advisories/GHSA-qhqf-ghgh-x2m4JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFocWYtZ2hnaC14Mm00
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 6 years ago
Updated: almost 2 years ago
CVSS Score: 7.3
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Percentage: 0.00126
EPSS Percentile: 0.47675
Identifiers: GHSA-qhqf-ghgh-x2m4, CVE-2017-0249
References:
- https://nvd.nist.gov/vuln/detail/CVE-2017-0249
- https://github.com/aspnet/Announcements/issues/239
- https://github.com/advisories/GHSA-qhqf-ghgh-x2m4
- https://github.com/Aiko-IT-Systems/DisCatSharp/security/advisories/GHSA-wj4j-gr3f-cfh7
Blast Radius: 10.4
Affected Packages
nuget:DisCatSharp
Dependent packages: 13Dependent repositories: 0
Downloads: 1,553,111 total
Affected Version Ranges: <= 9.8.3
No known fixed version
All affected versions: 9.5.8, 9.6.0, 9.6.1, 9.6.2, 9.7.0, 9.8.0, 9.8.1, 9.8.2, 9.8.3
nuget:Microsoft.AspNetCore.Mvc.WebApiCompatShim
Dependent packages: 40Dependent repositories: 0
Downloads: 130,791,086 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ViewFeatures
Dependent packages: 539Dependent repositories: 0
Downloads: 294,928,646 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.TagHelpers
Dependent packages: 106Dependent repositories: 0
Downloads: 240,923,357 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor
Dependent packages: 151Dependent repositories: 0
Downloads: 261,701,305 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Razor.Host
Dependent packages: 2Dependent repositories: 0
Downloads: 19,250,967 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8
nuget:Microsoft.AspNetCore.Mvc.Localization
Dependent packages: 38Dependent repositories: 0
Downloads: 233,724,650 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Xml
Dependent packages: 33Dependent repositories: 0
Downloads: 67,765,246 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Formatters.Json
Dependent packages: 263Dependent repositories: 0
Downloads: 520,452,206 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.18, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.DataAnnotations
Dependent packages: 84Dependent repositories: 0
Downloads: 380,846,913 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Cors
Dependent packages: 34Dependent repositories: 0
Downloads: 232,948,025 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.ApiExplorer
Dependent packages: 57Dependent repositories: 0
Downloads: 342,189,522 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0
nuget:Microsoft.AspNetCore.Mvc.Abstractions
Dependent packages: 783Dependent repositories: 0
Downloads: 756,160,410 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.37, 2.1.38, 2.2.0
nuget:System.Net.WebSockets.Client
Dependent packages: 82Dependent repositories: 0
Downloads: 175,455,440 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Net.Security
Dependent packages: 151Dependent repositories: 0
Downloads: 513,346,592 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.3.1, 4.3.2
nuget:System.Net.Http.WinHttpHandler
Dependent packages: 88Dependent repositories: 0
Downloads: 118,628,417 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.3.1, 4.3.2, 4.3.3, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 6.0.0, 6.0.1, 7.0.0, 8.0.0, 8.0.1, 8.0.2, 9.0.0
nuget:System.Text.Encodings.Web
Dependent packages: 1,161Dependent repositories: 0
Downloads: 3,378,039,299 total
Affected Version Ranges: = 4.3.0, = 4.0.0
Fixed in: 4.3.1, 4.0.1
All affected versions: 4.0.0, 4.3.0
All unaffected versions: 4.0.1, 4.3.1, 4.4.0, 4.5.0, 4.5.1, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 5.0.0, 5.0.1, 6.0.0, 6.0.1, 7.0.0, 8.0.0, 9.0.0
nuget:System.Net.Http
Dependent packages: 2,306Dependent repositories: 10
Downloads: 2,474,048,714 total
Affected Version Ranges: = 4.3.1, = 4.1.1
Fixed in: 4.3.2, 4.1.2
All affected versions: 4.1.1, 4.3.1
All unaffected versions: 2.0.20505, 2.0.20710, 4.0.0, 4.1.0, 4.1.2, 4.1.3, 4.1.4, 4.3.0, 4.3.2, 4.3.3, 4.3.4
nuget:Microsoft.AspNetCore.Mvc.Core
Dependent packages: 2,433Dependent repositories: 0
Downloads: 780,395,670 total
Affected Version Ranges: >= 1.1.0, < 1.1.3, >= 1.0.0, < 1.0.4
Fixed in: 1.1.3, 1.0.4
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.11, 2.1.16, 2.1.34, 2.1.38, 2.2.0, 2.2.2, 2.2.5
nuget:Microsoft.AspNetCore.Mvc
Dependent packages: 1,440Dependent repositories: 27
Downloads: 231,339,955 total
Affected Version Ranges: >= 1.0.0, < 1.0.4, >= 1.1.0, < 1.1.3
Fixed in: 1.0.4, 1.1.3
All affected versions: 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.1.0, 1.1.1, 1.1.2
All unaffected versions: 1.0.4, 1.0.5, 1.0.6, 1.1.3, 1.1.4, 1.1.5, 1.1.6, 1.1.7, 1.1.8, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.2.0