A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade aspnetcore-targeting-pack-3.1Upgrade dotnet-templates-3.1Upgrade dotnet3.1-debuginfoUpgrade aspnetcore-runtime-3.1Upgrade dotnet-apphost-pack-3.1-debuginfoUpgrade dotnet-runtime-3.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnetUpgrade dotnet-hostfxr-3.1Upgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-hostUpgrade dotnet-sdk-3.1Upgrade dotnet-sdk-3.1-debuginfoUpgrade dotnet-hostfxr-3.1-debuginfoUpgrade dotnet-host-debuginfoUpgrade dotnet-targeting-pack-3.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet3.1-debugsource | Aug 12, 2020 | Aug 11, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017. | Jun 25, 2025 | Aug 11, 2020 |
| Oracle_linux | — | Upgrade dotnet-hostUpgrade dotnetUpgrade dotnet-runtime-3.1Upgrade dotnet-sdk-3.1Upgrade aspnetcore-targeting-pack-3.1Upgrade aspnetcore-runtime-3.1Upgrade dotnet-templates-3.1Upgrade dotnet-apphost-pack-3.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-hostfxr-3.1 | Aug 17, 2020 | Aug 11, 2020 |
| Redhat_linux | — | Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-hostUpgrade aspnetcore-targeting-pack-3.1Upgrade dotnet-apphost-pack-3.1-debuginfoUpgrade dotnet-templates-3.1Upgrade dotnet-runtime-3.1Upgrade dotnet-apphost-pack-3.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-host-debuginfoUpgrade aspnetcore-runtime-3.1Upgrade dotnet-hostfxr-3.1Upgrade dotnetUpgrade dotnet3.1-debugsourceUpgrade dotnet-hostfxr-3.1-debuginfoUpgrade dotnet3.1-debuginfoUpgrade dotnet-sdk-3.1-debuginfoUpgrade dotnet-sdk-3.1 | Aug 12, 2020 | Aug 11, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Aug 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub