Microsoft ASP.NET Core 3.1.7

CPE Details

Microsoft ASP.NET Core 3.1.7
3.1.7
2021-07-07
16h44 +00:00
2021-07-07
17h51 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:microsoft:asp.net_core:3.1.7:*:*:*:*:*:*:*

Informations

Vendor

microsoft

Product

asp.net_core

Version

3.1.7

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-34532 2021-08-12 16h12 +00:00 ASP.NET Core and Visual Studio Information Disclosure Vulnerability
5.5
Medium
CVE-2021-1723 2021-01-12 18h42 +00:00 ASP.NET Core and Visual Studio Denial of Service Vulnerability
7.5
High
CVE-2020-1045 2020-09-10 22h00 +00:00

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.

The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.

The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.

7.5
High