A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-hostUpgrade dotnet-runtime-3.1Upgrade dotnet-apphost-pack-3.1-debuginfoUpgrade dotnet-sdk-3.1Upgrade aspnetcore-targeting-pack-3.1Upgrade dotnetUpgrade aspnetcore-runtime-3.1Upgrade dotnet-hostfxr-3.1Upgrade dotnet3.1-debuginfoUpgrade dotnet-templates-3.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-host-debuginfoUpgrade dotnet-sdk-3.1-debuginfoUpgrade dotnet3.1-debugsourceUpgrade dotnet-hostfxr-3.1-debuginfo | Aug 12, 2020 | Aug 11, 2020 |
| Microsoft Visual_studio | — | Update Microsoft Visual Studio 2017 to the latest version in the LTSC 15.9 version stream, or upgrade to a newer supported version of Visual Studio 2017.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.4 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.0 version stream, or upgrade to a newer supported version of Visual Studio 2019.Update Microsoft Visual Studio 2019 to the latest version in the LTSC 16.7 version stream, or upgrade to a newer supported version of Visual Studio 2019. | Jun 25, 2025 | Aug 11, 2020 |
| Oracle_linux | — | Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-targeting-pack-3.1Upgrade dotnet-hostfxr-3.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet-sdk-3.1Upgrade dotnet-templates-3.1Upgrade aspnetcore-targeting-pack-3.1Upgrade aspnetcore-runtime-3.1Upgrade dotnetUpgrade dotnet-hostUpgrade dotnet-runtime-3.1 | Aug 17, 2020 | Aug 11, 2020 |
| Redhat_linux | — | Upgrade dotnet-apphost-pack-3.1-debuginfoUpgrade aspnetcore-targeting-pack-3.1Upgrade dotnet-targeting-pack-3.1Upgrade netstandard-targeting-pack-2.1Upgrade dotnet-host-debuginfoUpgrade dotnet-runtime-3.1Upgrade dotnet-apphost-pack-3.1Upgrade dotnet-runtime-3.1-debuginfoUpgrade dotnet-hostUpgrade dotnet-templates-3.1Upgrade aspnetcore-runtime-3.1Upgrade dotnet-sdk-3.1Upgrade dotnet3.1-debugsourceUpgrade dotnet-sdk-3.1-debuginfoUpgrade dotnet-hostfxr-3.1Upgrade dotnet3.1-debuginfoUpgrade dotnet-hostfxr-3.1-debuginfoUpgrade dotnet | Aug 12, 2020 | Aug 11, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jul 2, 2025 | Aug 17, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub