CVE-2017-0256
5.3
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
Affected (101)
Products: Microsoft: Asp.net Model View Controller, Microsoft.aspnetcore.mvc.abstractions, Microsoft.aspnetcore.mvc.apiexplorer, Microsoft.aspnetcore.mvc.cors, Microsoft.aspnetcore.mvc.dataannotations, Microsoft.aspnetcore.mvc.formatters.json, Microsoft.aspnetcore.mvc.formatters.xml, Microsoft.aspnetcore.mvc.localization, Microsoft.aspnetcore.mvc.razor, Microsoft.aspnetcore.mvc.razor.host, Microsoft.aspnetcore.mvc.taghelpers, Microsoft.aspnetcore.mvc.viewfeatures, Microsoft.aspnetcore.mvc.webapicompatshim, System.net.http, System.net.http.winhttphandler, System.net.security, System.net.websockets.client, System.text.encodings.web
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 1.0.0 | |
| Version 4.1.1 | |
| Version 4.0.1 | |
| Version 4.0.0 | |
| Version 4.0.0 | |
| Version 4.0.0 |
References (2)
Source: secure@microsoft.com
Technical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical DescriptionThird Party Advisory
Timeline
No history available yet.