445
VMScore

CVE-2020-1045

Published: 11/09/2020 Updated: 31/12/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious malicious user to set a second cookie with the name being percent encoded.</p> <p>The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.</p>

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft asp.net core

fedoraproject fedora 32

fedoraproject fedora 33

redhat enterprise linux 8.0

redhat enterprise linux eus 8.2

redhat enterprise linux aus 8.2

redhat enterprise linux tus 8.2

redhat enterprise linux aus 8.4

redhat enterprise linux tus 8.4

redhat enterprise linux eus 8.4

redhat enterprise linux eus 8.6

redhat enterprise linux tus 8.6

redhat enterprise linux aus 8.6

Vendor Advisories

Synopsis Important: NET Core 31 security and bugfix update for Red Hat Enterprise Linux Type/Severity Security Advisory: Important Topic An update for rh-dotnet31-dotnet is now available for NET Core on Red Hat Enterprise LinuxRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: NET Core 31 security and bugfix update Type/Severity Security Advisory: Important Topic An update for NET Core 31 is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sy ...