CVE-2017-0248
EPSS 1.1%Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core
發布日:2018/10/16修改日:2024/12/5
描述
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
受影響套件(19)
- NuGet/Microsoft.AspNetCore.Mvc>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Abstractions>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ApiExplorer>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Core>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Cors>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.DataAnnotations>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Json>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Xml>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Localization>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor.Host>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.TagHelpers>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ViewFeatures>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.WebApiCompatShim>= 1.0.0, < 1.0.4
- NuGet/System.Net.Http>= 4.1.1, < 4.1.2
- NuGet/System.Net.Http.WinHttpHandler>= 4.0.0, < 4.0.1
- NuGet/System.Net.Security>= 4.0.0, < 4.0.1
- NuGet/System.Net.WebSockets.Client>= 4.0.0, < 4.0.1
- NuGet/System.Text.Encodings.Web>= 4.0.0, < 4.0.1