GHSA-6xh7-4v2w-36q6

Suggest an improvement
Source
https://github.com/advisories/GHSA-6xh7-4v2w-36q6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-6xh7-4v2w-36q6/GHSA-6xh7-4v2w-36q6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6xh7-4v2w-36q6
Aliases
  • CVE-2017-0247
Published
2018-10-16T19:58:05Z
Modified
2023-11-08T03:58:40.064574Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
ASP.NET Core fails to properly validate web requests
Details

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Database specific
{
    "nvd_published_at": "2017-05-12T14:29:00Z",
    "github_reviewed_at": "2020-06-16T21:20:41Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20"
    ]
}
References

Affected packages

NuGet / Microsoft.AspNetCore.Mvc

Package

Name
Microsoft.AspNetCore.Mvc
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc

Package

Name
Microsoft.AspNetCore.Mvc
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Core

Package

Name
Microsoft.AspNetCore.Mvc.Core
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Core

Package

Name
Microsoft.AspNetCore.Mvc.Core
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / System.Net.Http

Package

Name
System.Net.Http
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Http

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.1.1
Fixed
4.1.2

Affected versions

4.*

4.1.1

NuGet / System.Net.Http

Package

Name
System.Net.Http
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Http

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.1
Fixed
4.3.2

Affected versions

4.*

4.3.1

NuGet / System.Text.Encodings.Web

Package

Name
System.Text.Encodings.Web
View open source insights on deps.dev
Purl
pkg:nuget/System.Text.Encodings.Web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Text.Encodings.Web

Package

Name
System.Text.Encodings.Web
View open source insights on deps.dev
Purl
pkg:nuget/System.Text.Encodings.Web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / System.Net.Http.WinHttpHandler

Package

Name
System.Net.Http.WinHttpHandler
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Http.WinHttpHandler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.Http.WinHttpHandler

Package

Name
System.Net.Http.WinHttpHandler
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Http.WinHttpHandler

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.5.4

Affected versions

4.*

4.3.0
4.3.1
4.3.2
4.3.3
4.4.0-preview1-25305-02
4.4.0-preview2-25405-01
4.4.0
4.5.0-preview1-26216-02
4.5.0-preview2-26406-04
4.5.0-rc1
4.5.0
4.5.1
4.5.2-servicing-27114-05
4.5.2
4.5.3

NuGet / System.Net.Security

Package

Name
System.Net.Security
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.Security

Package

Name
System.Net.Security
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.Security

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / System.Net.WebSockets.Client

Package

Name
System.Net.WebSockets.Client
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.WebSockets.Client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.0.1

Affected versions

4.*

4.0.0

NuGet / System.Net.WebSockets.Client

Package

Name
System.Net.WebSockets.Client
View open source insights on deps.dev
Purl
pkg:nuget/System.Net.WebSockets.Client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.1

Affected versions

4.*

4.3.0

NuGet / Microsoft.AspNetCore.Mvc.Abstractions

Package

Name
Microsoft.AspNetCore.Mvc.Abstractions
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Abstractions

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Abstractions

Package

Name
Microsoft.AspNetCore.Mvc.Abstractions
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Abstractions

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.ApiExplorer

Package

Name
Microsoft.AspNetCore.Mvc.ApiExplorer
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.ApiExplorer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.ApiExplorer

Package

Name
Microsoft.AspNetCore.Mvc.ApiExplorer
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.ApiExplorer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Cors

Package

Name
Microsoft.AspNetCore.Mvc.Cors
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Cors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Cors

Package

Name
Microsoft.AspNetCore.Mvc.Cors
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Cors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.DataAnnotations

Package

Name
Microsoft.AspNetCore.Mvc.DataAnnotations
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.DataAnnotations

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.DataAnnotations

Package

Name
Microsoft.AspNetCore.Mvc.DataAnnotations
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.DataAnnotations

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Json

Package

Name
Microsoft.AspNetCore.Mvc.Formatters.Json
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Formatters.Json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Json

Package

Name
Microsoft.AspNetCore.Mvc.Formatters.Json
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Formatters.Json

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Xml

Package

Name
Microsoft.AspNetCore.Mvc.Formatters.Xml
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Formatters.Xml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Formatters.Xml

Package

Name
Microsoft.AspNetCore.Mvc.Formatters.Xml
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Formatters.Xml

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Localization

Package

Name
Microsoft.AspNetCore.Mvc.Localization
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Localization

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Localization

Package

Name
Microsoft.AspNetCore.Mvc.Localization
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Localization

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Razor.Host

Package

Name
Microsoft.AspNetCore.Mvc.Razor.Host
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Razor.Host

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Razor.Host

Package

Name
Microsoft.AspNetCore.Mvc.Razor.Host
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Razor.Host

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.Razor

Package

Name
Microsoft.AspNetCore.Mvc.Razor
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Razor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.Razor

Package

Name
Microsoft.AspNetCore.Mvc.Razor
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.Razor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.TagHelpers

Package

Name
Microsoft.AspNetCore.Mvc.TagHelpers
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.TagHelpers

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.TagHelpers

Package

Name
Microsoft.AspNetCore.Mvc.TagHelpers
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.TagHelpers

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.ViewFeatures

Package

Name
Microsoft.AspNetCore.Mvc.ViewFeatures
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.ViewFeatures

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.ViewFeatures

Package

Name
Microsoft.AspNetCore.Mvc.ViewFeatures
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.ViewFeatures

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2

NuGet / Microsoft.AspNetCore.Mvc.WebApiCompatShim

Package

Name
Microsoft.AspNetCore.Mvc.WebApiCompatShim
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.WebApiCompatShim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.0.4

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3

NuGet / Microsoft.AspNetCore.Mvc.WebApiCompatShim

Package

Name
Microsoft.AspNetCore.Mvc.WebApiCompatShim
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.AspNetCore.Mvc.WebApiCompatShim

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.3

Affected versions

1.*

1.1.0
1.1.1
1.1.2