QID 982022

QID 982022: Dotnet (nuget) Security Update for Microsoft.AspNetCore.Mvc.WebApiCompatShim (GHSA-j8f4-2w4p-mhjc)

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-j8f4-2w4p-mhjc for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982022

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Abstractions URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.ApiExplorer URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Core URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Cors URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.DataAnnotations URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Formatters.Json URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Formatters.Xml URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Localization URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Razor URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.Razor.Host URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.TagHelpers URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.ViewFeatures URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc Microsoft.AspNetCore.Mvc.WebApiCompatShim URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc System.Net.Http URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc System.Net.Http.WinHttpHandler URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc System.Net.Security URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc System.Net.WebSockets.Client URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc
    GHSA-j8f4-2w4p-mhjc System.Text.Encodings.Web URL Logo github.com/advisories/GHSA-j8f4-2w4p-mhjc