CVE-2019-0548Uncontrolled Resource Consumption in Microsoft Asp.net Core

Severity
7.5HIGHNVD
EPSS
6.7%
top 8.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 14

Description

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5microsoft/asp.net_core2.1, 2.2+1
NVDmicrosoft/asp.net_core2.1, 2.2+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9pfr-cc3p-p98q: A denial of service vulnerability exists when ASP2022-05-14
GHSA
Denial of service in ASP.NET Core2022-05-14
CVEList
CVE-2019-0548: A denial of service vulnerability exists when ASP2019-01-08

📋Vendor Advisories

3
Microsoft
ASP.NET Core Denial of Service Vulnerability2019-01-08
Red Hat
Core: AspNetCoreModule WebSocket DOS2019-01-08
Red Hat
Core: Kestrel - WebSocket DoS via CancellationToken (CoreFX and ASP.NET)2019-01-08

💬Community

1
Bugzilla
CVE-2019-0548 Asp.NET Core: AspNetCoreModule WebSocket DOS2018-12-18
CVE-2019-0548 — Uncontrolled Resource Consumption | cvebase