CVE-2017-0256
MEDIUM5.3EPSS 4.3%Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc
Published: 10/16/2018Modified: 11/8/2023
Description
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
Affected packages (19)
- NuGet/Microsoft.AspNetCore.Mvc>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Abstractions>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ApiExplorer>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Core>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Cors>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.DataAnnotations>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Json>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Xml>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Localization>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor.Host>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.TagHelpers>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ViewFeatures>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.WebApiCompatShim>= 1.0.0, < 1.0.4
- NuGet/System.Net.Http>= 4.1.1, < 4.1.2
- NuGet/System.Net.Http.WinHttpHandler>= 4.0.0, < 4.0.1
- NuGet/System.Net.Security>= 4.0.0, < 4.0.1
- NuGet/System.Net.WebSockets.Client>= 4.0.0, < 4.0.1
- NuGet/System.Text.Encodings.Web>= 4.0.0, < 4.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |