Skip to content

Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core

Moderate severity GitHub Reviewed Published Oct 16, 2018 to the GitHub Advisory Database • Updated Feb 28, 2024

Package

nuget Microsoft.AspNetCore.Mvc (NuGet)

Affected versions

>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3

Patched versions

1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Abstractions (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.ApiExplorer (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Core (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Cors (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.DataAnnotations (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Formatters.Json (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Formatters.Xml (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Localization (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Razor (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.Razor.Host (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.TagHelpers (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.ViewFeatures (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget Microsoft.AspNetCore.Mvc.WebApiCompatShim (NuGet)
>= 1.0.0, < 1.0.4
>= 1.1.0, < 1.1.3
1.0.4
1.1.3
nuget System.Net.Http (NuGet)
= 4.1.1
= 4.3.1
4.1.2
4.3.2
nuget System.Net.Http.WinHttpHandler (NuGet)
= 4.0.0
= 4.3.0
4.0.1
4.3.1
nuget System.Net.Security (NuGet)
= 4.0.0
= 4.3.0
4.0.1
4.3.1
nuget System.Net.WebSockets.Client (NuGet)
= 4.0.0
= 4.3.0
4.0.1
4.3.1
nuget System.Text.Encodings.Web (NuGet)
= 4.0.0
= 4.3.0
4.0.1
4.3.1

Description

Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."

References

Published to the GitHub Advisory Database Oct 16, 2018
Reviewed Jun 16, 2020
Last updated Feb 28, 2024

Severity

Moderate

EPSS score

0.208%
(60th percentile)

Weaknesses

CVE ID

CVE-2017-0248

GHSA ID

GHSA-ch6p-4jcm-h8vh

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.