CVE-2017-0249
HIGH7.3EPSS 5.8%High severity vulnerability that affects Microsoft.AspNetCore.Mvc
發布日:2018/10/16修改日:2023/11/8
描述
See https://nvd.nist.gov/vuln/detail/CVE-2017-0249 & https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0249
受影響套件(20)
- NuGet/DisCatSharpfrom 0, <= 9.8.3
- NuGet/Microsoft.AspNetCore.Mvc>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Abstractions>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ApiExplorer>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Core>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Cors>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.DataAnnotations>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Json>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Formatters.Xml>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Localization>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.Razor.Host>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.TagHelpers>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.ViewFeatures>= 1.0.0, < 1.0.4
- NuGet/Microsoft.AspNetCore.Mvc.WebApiCompatShim>= 1.0.0, < 1.0.4
- NuGet/System.Net.Http>= 4.1.1, < 4.1.2
- NuGet/System.Net.Http.WinHttpHandler>= 4.0.0, < 4.0.1
- NuGet/System.Net.Security>= 4.0.0, < 4.0.1
- NuGet/System.Net.WebSockets.Client>= 4.0.0, < 4.0.1
- NuGet/System.Text.Encodings.Web>= 4.0.0, < 4.0.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |