Microsoft Asp.Net Core 3.1 vulnerabilities
5 known vulnerabilities affecting microsoft/asp.net_core_3.1.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-43877HIGHCVSS 7.8≥ 3.0, < 3.1.222021-12-15
CVE-2021-43877 [HIGH] CVE-2021-43877: ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2021-34532MEDIUMCVSS 5.5≥ 3.0, < 3.1.182021-08-12
CVE-2021-34532 [MEDIUM] CVE-2021-34532: ASP.NET Core and Visual Studio Information Disclosure Vulnerability
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
cvelistv5nvd
CVE-2021-1723HIGHCVSS 7.5≥ 3.0, < publication2021-01-12
CVE-2021-1723 [HIGH] CVE-2021-1723: ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
cvelistv5nvd
CVE-2020-1045HIGHCVSS 7.5≥ 3.0, < publication2020-09-11
CVE-2020-1045 [HIGH] CVE-2020-1045: <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded c
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.
The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.
The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie par
cvelistv5nvd
CVE-2020-1597HIGHCVSS 7.5≥ 3.0, < publication2020-08-17
CVE-2020-1597 [HIGH] CVE-2020-1597: A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attac
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.
A remote unauthenticated attacker could exploit this vulnerability by i
cvelistv5nvd