Rapid7 Vulnerability & Exploit Database

Oracle Linux: (CVE-2020-1045) ELSA-2020-3699: .NET Core 3.1 security and bugfix update

Back to Search

Oracle Linux: (CVE-2020-1045) ELSA-2020-3699: .NET Core 3.1 security and bugfix update

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
09/11/2020
Created
09/15/2020
Added
09/12/2020
Modified
09/18/2020

Description

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'.

Solution(s)

  • oracle-linux-upgrade-aspnetcore-runtime
  • oracle-linux-upgrade-aspnetcore-targeting-pack
  • oracle-linux-upgrade-dotnet
  • oracle-linux-upgrade-dotnet-apphost-pack
  • oracle-linux-upgrade-dotnet-host
  • oracle-linux-upgrade-dotnet-hostfxr
  • oracle-linux-upgrade-dotnet-runtime
  • oracle-linux-upgrade-dotnet-sdk
  • oracle-linux-upgrade-dotnet-targeting-pack
  • oracle-linux-upgrade-dotnet-templates
  • oracle-linux-upgrade-dotnet3-1
  • oracle-linux-upgrade-netstandard-targeting-pack

References

  • oracle-linux-upgrade-aspnetcore-runtime
  • oracle-linux-upgrade-aspnetcore-targeting-pack
  • oracle-linux-upgrade-dotnet
  • oracle-linux-upgrade-dotnet-apphost-pack
  • oracle-linux-upgrade-dotnet-host
  • oracle-linux-upgrade-dotnet-hostfxr
  • oracle-linux-upgrade-dotnet-runtime
  • oracle-linux-upgrade-dotnet-sdk
  • oracle-linux-upgrade-dotnet-targeting-pack
  • oracle-linux-upgrade-dotnet-templates
  • oracle-linux-upgrade-dotnet3-1
  • oracle-linux-upgrade-netstandard-targeting-pack

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;