icon

We found results for “

WS-2018-0608

Good to know:

icon
icon

Date: May 8, 2018

A vulnerability was discovered in versions 2.x of ASP.NET Core where a specially crafted request can cause excess resource consumption in Kestrel.

Language: C#

Severity Score

Severity Score

Weakness Type (CWE)

Uncontrolled Resource Consumption

CWE-400

Top Fix

icon

Upgrade Version

Upgrade to version Musement.LambdaExec - no_fix;ReactES6.Web - 0.0.4;Microsoft.AspNetCore.Server.Kestrel.Core - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Core - 2.0.3;Microsoft.AspNetCore.Server.Kestrel.Core - 2.0.0-preview1-final;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.0.0-preview1-final;Microsoft.AspNetCore.Server.Kestrel.Transport.Abstractions - 2.0.3;Microsoft.AspNetCore.All - 2.0.0-preview1-final;Microsoft.AspNetCore.All - 2.0.8;Microsoft.AspNetCore.All - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.0.3;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.1.1;Microsoft.AspNetCore.Server.Kestrel.Transport.Libuv - 2.0.0-preview1-final;MicrosoftDynamicsManager - 1.0.1;Swashbuckle.AspNetCore.Cli - 5.0.0;lunet - 0.1.0-alpha.2;VirtoCommerce.GlobalTool - 3.0.0-beta0009;Plexus.Interop.Broker.Redist-win-x86 - 0.2.5;Diffstore.DBMS - no_fix;Xam.Plugin.LiveSync - no_fix;Microsoft.ServiceFabric.VolumeDriver - no_fix;SourceBrowser - 1.0.19;Microsoft.ServiceFabric.AzureFiles.VolumePlugin - no_fix;Stubby.ConsoleRunner - no_fix;ind-studio-scada - no_fix;MarkdownPages.CLI - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us