CVE-2022-29145
published 2022-05-10CVE-2022-29145: .NET and Visual Studio Denial of Service Vulnerability
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.76%
90.9th percentile
.NET and Visual Studio Denial of Service Vulnerability
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-arm64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-arm64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-musl-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.linux-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 3.0.0 < 3.1.25 | 3.1.25 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 5.0.0 < 5.0.17 | 5.0.17 |
| microsoft | microsoft.aspnetcore.app.runtime.osx-x64 | >= 6.0.0 < 6.0.5 | 6.0.5 |
| microsoft | microsoft.aspnetcore.app.runtime.win-arm | >= 3.0.0 < 3.1.25 | 3.1.25 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET and Visual Studio Denial of Service Vulnerability
vendor_msrc·2022-05-10·CVSS 7.5
CVE-2022-29145 [HIGH] .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio: .NET and Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014330
Reference: https://support.microsoft.com/help/5014330
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014326
Reference: https://support.microsoft.com/help/5014326
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5014329
Reference: https://support.microsoft.com/help/5014329
Remediation: Release Notes
Reference: https://my.visualstu
Red Hat
dotnet: parsing HTML causes Denial of Service
vendor_redhat·2022-05-10·CVSS 7.5
CVE-2022-29145 [HIGH] CWE-835 dotnet: parsing HTML causes Denial of Service
dotnet: parsing HTML causes Denial of Service
.NET and Visual Studio Denial of Service Vulnerability
A flaw was found in dotnet. The Microsoft Security Advisory describes the issue of the ASP.NET FormFeature.cs causing a denial of service when HTML forms are parsed.
Statement: Affected .NET versions: 6.0, 5.0, 3.1
OSV
.NET Denial of Service Vulnerability
osv·2022-08-30
CVE-2022-29145 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET core 3.1 where a malicious client can can cause a denial of service when HTML forms are parsed.
### Affected software
* Any .NET 6.0 application running on .NET 6.0.4 or earlier.
* Any .NET 5.0 application running .NET 5.0.16 or earlier.
* Any .NET Core 3.1 application running on .NET Core 3.1.24 or earlier.
#### Affected packages
**.NET Core 3.1**
| Package name | Affected version | Patched version |
|------------------------------------------
GHSA
.NET Denial of Service Vulnerability
ghsa·2022-08-30
CVE-2022-29145 [HIGH] .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 6.0, .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
A vulnerability exists in .NET 6.0, .NET 5.0 and .NET core 3.1 where a malicious client can can cause a denial of service when HTML forms are parsed.
### Affected software
* Any .NET 6.0 application running on .NET 6.0.4 or earlier.
* Any .NET 5.0 application running .NET 5.0.16 or earlier.
* Any .NET Core 3.1 application running on .NET Core 3.1.24 or earlier.
#### Affected packages
**.NET Core 3.1**
| Package name | Affected version | Patched version |
|------------------------------------------
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-29145https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNXQL7EZORGU4PZCPJ5EPQ4P7IEY3ZZO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IBYSBUDJYQ76HK4TULXVIIPCKK2U6WDB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W5FPEQ6BTYRGTS6IYCDTZW6YF5HLQ3BY/https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-29145
2022-05-10
Published