Lucene search

K
githubGitHub Advisory DatabaseGHSA-3CF7-7WQ6-8842
HistoryMay 24, 2022 - 5:18 p.m.

ASP.NET Core Denial of Service Vulnerability

2022-05-2417:18:32
CWE-20
GitHub Advisory Database
github.com
15
denial of service
asp.net core
vulnerability
web requests

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

50.4%

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka ‘ASP.NET Core Denial of Service Vulnerability’.

Affected configurations

Vulners
Node
microsoftpublisherRange3.1.03.1.4x86
OR
microsoftwordRange3.1.03.1.4x64
OR
microsoftaspnetcore.app.runtime.win-armRange3.1.03.1.4
OR
microsoftwordRange3.1.03.1.4x64
OR
microsoftwordRange3.1.03.1.4x64
OR
microsoftwordRange3.1.03.1.4x64
OR
microsoftaspnetcore.app.runtime.linux-musl-arm64Range3.1.03.1.4
OR
microsoftaspnetcore.app.runtime.linux-arm64Range3.1.03.1.4
OR
microsoftaspnetcore.app.runtime.linux-armRange3.1.03.1.4
VendorProductVersionCPE
microsoftpublisher*cpe:2.3:a:microsoft:publisher:*:*:*:*:*:*:x86:*
microsoftword*cpe:2.3:a:microsoft:word:*:*:*:*:*:*:x64:*
microsoftaspnetcore.app.runtime.win-arm*cpe:2.3:a:microsoft:aspnetcore.app.runtime.win-arm:*:*:*:*:*:*:*:*
microsoftaspnetcore.app.runtime.linux-musl-arm64*cpe:2.3:a:microsoft:aspnetcore.app.runtime.linux-musl-arm64:*:*:*:*:*:*:*:*
microsoftaspnetcore.app.runtime.linux-arm64*cpe:2.3:a:microsoft:aspnetcore.app.runtime.linux-arm64:*:*:*:*:*:*:*:*
microsoftaspnetcore.app.runtime.linux-arm*cpe:2.3:a:microsoft:aspnetcore.app.runtime.linux-arm:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

50.4%