5
CVSSv2

CVE-2020-1045

Published: 11/09/2020 Updated: 16/09/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious malicious user to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'.

Vulnerability Trend

Vendor Advisories

Synopsis Important: NET Core 31 security and bugfix update for Red Hat Enterprise Linux Type/Severity Security Advisory: Important Topic An update for rh-dotnet31-dotnet is now available for NET Core on Red Hat Enterprise LinuxRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: NET Core 31 security and bugfix update Type/Severity Security Advisory: Important Topic An update for NET Core 31 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sy ...