GHSA-7mfr-774f-w5r9

Suggest an improvement
Source
https://github.com/advisories/GHSA-7mfr-774f-w5r9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-7mfr-774f-w5r9/GHSA-7mfr-774f-w5r9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7mfr-774f-w5r9
Aliases
  • CVE-2017-11770
Published
2022-04-12T00:07:34Z
Modified
2023-11-08T03:58:49.964848Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Improper Certificate Validation
Details

.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2022-04-12T00:07:34Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-295"
    ]
}
References

Affected packages

NuGet / System.Security.Cryptography.X509Certificates

Package

Name
System.Security.Cryptography.X509Certificates
View open source insights on deps.dev
Purl
pkg:nuget/System.Security.Cryptography.X509Certificates

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.1.2

Affected versions

4.*

4.1.0-rc2-24027
4.1.0
4.1.1

NuGet / Microsoft.NETCore.App

Package

Name
Microsoft.NETCore.App
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.NETCore.App

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
2.0.3

Affected versions

1.*

1.0.0
1.0.1
1.0.3
1.0.4
1.0.5-servicing-004880-00
1.0.5
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.1.0-preview1-001100-00
1.1.0
1.1.1
1.1.2
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13

2.*

2.0.0-preview1-002111-00
2.0.0-preview2-25407-01
2.0.0