QID 982023

QID 982023: Dotnet (nuget) Security Update for System.Net.Http.WinHttpHandler (GHSA-6xh7-4v2w-36q6)

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-6xh7-4v2w-36q6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982023

    Software Advisories
    Advisory ID Software Component Link
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Abstractions URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.ApiExplorer URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Core URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Cors URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.DataAnnotations URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Formatters.Json URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Formatters.Xml URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Localization URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Razor URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.Razor.Host URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.TagHelpers URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.ViewFeatures URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 Microsoft.AspNetCore.Mvc.WebApiCompatShim URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 System.Net.Http URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 System.Net.Http.WinHttpHandler URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 System.Net.Security URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 System.Net.WebSockets.Client URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6
    GHSA-6xh7-4v2w-36q6 System.Text.Encodings.Web URL Logo github.com/advisories/GHSA-6xh7-4v2w-36q6