CVE-2020-1045
HIGH7.5EPSS 20.4%Microsoft ASP.NET Core Security Feature Bypass Vulnerability
發布日:2022/5/24修改日:2025/5/20
描述
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>
受影響套件(14)
- Bitnami/aspnet-core>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.Appfrom 0, < 2.1.22
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-arm64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-arm64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-musl-x64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.linux-x64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.osx-x64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.win-arm>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.win-arm64>= 3.1.5, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x64>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.App.Runtime.win-x86>= 3.1.0, < 3.1.8
- NuGet/Microsoft.AspNetCore.Httpfrom 0, < 2.1.22
- NuGet/Microsoft.Owinfrom 0, < 4.1.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
參考連結(16)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2020-1045
- WEBhttps://access.redhat.com/errata/RHSA-2020:3699
- WEBhttps://github.com/dotnet/announcements/issues/165
- WEBhttps://github.com/dotnet/aspnetcore/issues/25701
- WEBhttps://github.com/dotnet/aspnetcore/issues/25701#issuecomment-689434477
- WEBhttps://github.com/dotnet/aspnetcore/pull/24264
- WEBhttps://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318
- WEBhttps://github.com/github/advisory-database/issues/302
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3
- WEBhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3
- WEBhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045
- WEBhttps://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600