CVE-2019-0564Uncontrolled Resource Consumption in Microsoft Asp.net Core

Severity
7.5HIGHNVD
EPSS
7.7%
top 8.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 8
Latest updateMay 14

Description

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0548.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
Denial of service in ASP.NET Core2022-05-14
OSV
Denial of service in ASP.NET Core2022-05-14
CVEList
CVE-2019-0564: A denial of service vulnerability exists when ASP2019-01-08

📋Vendor Advisories

3
Microsoft
ASP.NET Core Denial of Service Vulnerability2019-01-08
Red Hat
Core: Kestrel - WebSocket DoS via CancellationToken (CoreFX and ASP.NET)2019-01-08
Red Hat
Core: AspNetCoreModule WebSocket DOS2019-01-08

💬Community

1
Bugzilla
CVE-2019-0564 Asp.NET Core: Kestrel - WebSocket DoS via CancellationToken (CoreFX and ASP.NET)2018-12-18
CVE-2019-0564 — Uncontrolled Resource Consumption | cvebase