Microsoft Asp.Net Core 2.1 vulnerabilities

5 known vulnerabilities affecting microsoft/asp.net_core_2.1.

Total CVEs
5
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2023-35391HIGHCVSS 7.5≥ 2.0, < 2.1.402023-08-08
CVE-2023-35391 [MEDIUM] CVE-2023-35391: ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
cvelistv5nvd
CVE-2023-38180HIGHCVSS 7.5KEV≥ 2.0, < 2.1.402023-08-08
CVE-2023-38180 [HIGH] CWE-400 CVE-2023-38180: .NET and Visual Studio Denial of Service Vulnerability .NET and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2021-34532MEDIUMCVSS 5.5≥ 2.0, < 2.1.292021-08-12
CVE-2021-34532 [MEDIUM] CVE-2021-34532: ASP.NET Core and Visual Studio Information Disclosure Vulnerability ASP.NET Core and Visual Studio Information Disclosure Vulnerability
cvelistv5nvd
CVE-2020-1045HIGHCVSS 7.5≥ 2.0, < publication2020-09-11
CVE-2020-1045 [HIGH] CVE-2020-1045: <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded c A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie par
cvelistv5nvd
CVE-2020-1597HIGHCVSS 7.5≥ 2.0, < publication2020-08-17
CVE-2020-1597 [HIGH] CVE-2020-1597: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attac A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by i
cvelistv5nvd