We found results for “”
WS-2018-0608
Good to know:
Date: May 8, 2018
A vulnerability was discovered in versions 2.x of ASP.NET Core where a specially crafted request can cause excess resource consumption in Kestrel.
Language: C#
Severity Score
Severity Score
Weakness Type (CWE)
Uncontrolled Resource Consumption
CWE-400Top Fix
Upgrade Version
Upgrade to version Musement.LambdaExec - no_fix;ReactES6.Web - 0.0.4;Microsoft.AspNetCore.Server.Kestrel.Core - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Core - 2.0.3;Microsoft.AspNetCore.Server.Kestrel.Core - 2.0.0-preview1-final;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.0.0-preview1-final;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.0.3;Microsoft.AspNetCore.All - 2.0.0-preview1-final;Microsoft.AspNetCore.All - 2.0.8;Microsoft.AspNetCore.All - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.0.3;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.0.0-preview1-final;MicrosoftDynamicsManager - 1.0.1;Swashbuckle.AspNetCore.Cli - 5.0.0;lunet - 0.1.0-alpha.2;VirtoCommerce.GlobalTool - 3.0.0-beta0009;Plexus.Interop.Broker.Redist-win-x86 - 0.2.5;Diffstore.DBMS - no_fix;Xam.Plugin.LiveSync - no_fix;Microsoft.ServiceFabric.VolumeDriver - no_fix;SourceBrowser - 1.0.19;Microsoft.ServiceFabric.AzureFiles.VolumePlugin - no_fix;Stubby.ConsoleRunner - no_fix;ind-studio-scada - no_fix;MarkdownPages.CLI - no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


