CVE-2018-8269
HIGH7.5EPSS 24.6%Denial of service in ASP.NET Core
Published: 10/16/2018Modified: 11/28/2024
Description
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Service Vulnerability." This affects Microsoft.Data.OData.
Affected packages (3)
- NuGet/Microsoft.AspNetCore.All>= 2.1.0, < 2.1.13
- NuGet/Microsoft.AspNetCore.DataProtection.AzureStorage>= 2.1.0, < 2.1.13
- NuGet/Microsoft.Data.ODatafrom 0, < 5.8.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
References (6)
- ADVISORYhttps://github.com/advisories/GHSA-mv2r-q4g5-j8q5
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2018-8269
- WEBhttps://github.com/aspnet/Announcements/issues/385
- WEBhttps://github.com/github/advisory-database/issues/302
- WEBhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8269
- WEBhttps://www.exploit-db.com/exploits/46101