Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2019-1075 #2598

Closed
asmundg opened this issue Dec 30, 2019 · 0 comments
Closed

CVE-2019-1075 #2598

asmundg opened this issue Dec 30, 2019 · 0 comments

Comments

@asmundg
Copy link
Contributor

asmundg commented Dec 30, 2019

The NSwag.MBuild nuget (and possibly others) appear to bundle DLLs affected by CVE-2019-1075: ASP.NET Core Spoofing Vulnerability (aspnet/Announcements#373).

From the upstream bug:

"Microsoft is aware of a spoofing vulnerability that exists in ASP.NET Core that could lead to an open redirect. An attacker who successfully exploited the vulnerability could redirect a targeted user to a malicious website.

To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link.

Affected software: Any ASP.NET Core based application that uses any of following vulnerable packages:

Package name Vulnerable versions Secure versions
Microsoft.AspNetCore.Server.HttpSys 2.1.0, 2.1.12.2.0 2.1.122.2.6
Microsoft.AspNetCore.Server.IIS 2.2.0, 2.2.1, 2.2.2 2.2.6
Microsoft.AspNetCore.All 2.1.0 - 2.1.112.2.0 - 2.2.5 2.1.122.2.6
Microsoft.AspNetCore.App 2.1.0 - 2.1.112.2.0 - 2.2.5 2.1.122.2.6

"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant