CVE-2020-1045
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
Cookie parsing failure
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | Microsoft.AspNetCore.Http | <2.1.22 | 2.1.22 |
| NuGet | Microsoft.AspNetCore.App | <2.1.22 | 2.1.22 |
| NuGet | Microsoft.Owin | <4.1.1 | 4.1.1 |
| NuGet | Microsoft.AspNetCore.App.Runtime.linux-arm | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.linux-arm64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.linux-musl-x64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.linux-x64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.osx-x64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-arm | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-x86 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 | >=3.1.0,<3.1.8 | 3.1.8 |
| NuGet | Microsoft.AspNetCore.App.Runtime.win-arm64 | >=3.1.5,<3.1.8 | 3.1.8 |
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-1045
- https://github.com/dotnet/announcements/issues/165
- https://github.com/dotnet/aspnetcore/issues/25701
- https://github.com/dotnet/aspnetcore/issues/25701#issuecomment-689434477
- https://github.com/github/advisory-database/issues/302
- https://github.com/dotnet/aspnetcore/pull/24264
- https://access.redhat.com/errata/RHSA-2020:3699
- https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045
- https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600
Verify integrity in audit chain (admin only). AS-IS.