CVE-2017-0256

Severity
5.3MEDIUM
EPSS
4.3%
top 11.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 12
Latest updateOct 16

Description

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages38 packages

NuGetMicrosoft.AspNetCore.Mvc1.0.01.0.4+1
NuGetMicrosoft.AspNetCore.Mvc.Core1.0.01.0.4+1
NuGetMicrosoft.AspNetCore.Mvc.Cors1.0.01.0.4+1
NuGetMicrosoft.AspNetCore.Mvc.Razor1.0.01.0.4+1
NuGetMicrosoft.AspNetCore.Mvc.Razor.Host1.0.01.0.4+1

🔴Vulnerability Details

3
GHSA
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc2018-10-16
OSV
Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc2018-10-16
CVEList
CVE-2017-0256: A spoofing vulnerability exists when the ASP2017-05-12

💬Community

1
Bugzilla
CVE-2016-7060 Red Hat QCI: qci exposes password in web UI when they should be masked2016-09-28
CVE-2017-0256 (MEDIUM CVSS 5.3) | A spoofing vulnerability exists whe | cvebase.io