CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
ASP.NET Core and Visual Studio Information Disclosure Vulnerability | 5.5 |
Medium |
||
ASP.NET Core and Visual Studio Denial of Service Vulnerability | 7.5 |
High |
||
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names. |
7.5 |
High |