Microsoft ASP.NET Core Security Feature Bypass Vulnerability
Published Sep 11, 2020
7.5
HIGHCVSS 3.1
EPSS 5.93%
Description
<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>
Affected products
-
- Version 2.0StatusaffectedConstraints<publication
- Version
-
- Version 3.0StatusaffectedConstraints<publication
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | ASP.NET Core 2.1 | n/a |
| ||||||
| Microsoft | ASP.NET Core 3.1 | n/a |
|
Configuration 1
- ≥ 2.1 · ≤ 2.1.21
- ≥ 3.1 · < 3.1.8
Configuration 2
- 32
- 33
Configuration 3
- 8.0
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
No data.
.NET Core on Red Hat Enterprise Linux
rh-dotnet31-dotnet-0:3.1.108-1.el7
Fixed · RHSA-2020:3697
Red Hat Enterprise Linux 8
dotnet3.1-0:3.1.108-2.el8_2
Fixed · RHSA-2020:3699
.NET Core 2.1 on Red Hat Enterprise Linux
rh-dotnet21
Not affected
Red Hat Enterprise Linux 8
dotnet
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet31-dotnet-0:3.1.108-1.el7 | Fixed | RHSA-2020:3697 |
| Red Hat Enterprise Linux 8 | dotnet3.1-0:3.1.108-2.el8_2 | Fixed | RHSA-2020:3699 |
| .NET Core 2.1 on Red Hat Enterprise Linux | rh-dotnet21 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The "Cookie Prefixes" feature is not used by default in ASP.NET. Successful exploitation likely requires a secondary vulnerability, for example a cross-site scripting issue.
References (19)
- https://access.redhat.com/errata/RHSA-2020:3699 Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-1045 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1873451 Issue Tracking
- https://github.com/advisories/GHSA-hxrm-9w7p-39cc Advisory
- https://github.com/dotnet/announcements/issues/165
- https://github.com/dotnet/aspnetcore/issues/23578
- https://github.com/dotnet/aspnetcore/issues/25701
- https://github.com/dotnet/aspnetcore/issues/25701#issuecomment-689434477
- https://github.com/dotnet/aspnetcore/pull/24264
- https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318 Release NotesThird Party Advisory
- https://github.com/github/advisory-database/issues/302
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/
- https://nvd.nist.gov/vuln/detail/CVE-2020-1045
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045 PatchVendor Advisory
- https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-1045
Change history (0)
No recorded changes yet.