Skip to content
This repository has been archived by the owner on Oct 31, 2024. It is now read-only.

microsoft.netcore.app.2.0.0.nupkg: 3 vulnerabilities (highest severity is: 7.5) #1

Open
mend-for-github-com bot opened this issue Aug 4, 2022 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@mend-for-github-com
Copy link

mend-for-github-com bot commented Aug 4, 2022

Vulnerable Library - microsoft.netcore.app.2.0.0.nupkg

A set of .NET API's that are included in the default .NET Core application model. e8b8861ac7faf042c87a5c2f9f2d04c98b69f28d When using NuGet 3.x this package requires at least version 3.4.

Library home page: https://api.nuget.org/packages/microsoft.netcore.app.2.0.0.nupkg

Path to dependency file: /NewVoiceMedia.Pci.Integration.csproj

Path to vulnerable library: /ft.netcore.app/2.0.0/microsoft.netcore.app.2.0.0.nupkg

Found in HEAD commit: 2b41f741fda6b99db25173d55071790a35ab3696

Vulnerabilities

CVE Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (microsoft.netcore.app.2.0.0.nupkg version) Remediation Possible** Reachability
CVE-2020-1108 High 7.5 Not Defined 0.1% microsoft.netcore.app.2.0.0.nupkg Direct Microsoft.NETCore.App - 2.1.18, Microsoft.NETCore.App.Runtime - 3.1.4
CVE-2018-8416 Medium 6.5 Not Defined 0.1% microsoft.netcore.app.2.0.0.nupkg Direct Microsoft.NETCore.App - 2.1.7
CVE-2018-8292 Medium 5.3 Not Defined 1.6% microsoft.netcore.app.2.0.0.nupkg Direct System.Net.Http - 4.3.4;Microsoft.PowerShell.Commands.Utility - 6.1.0-rc.1

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2020-1108

Vulnerable Library - microsoft.netcore.app.2.0.0.nupkg

A set of .NET API's that are included in the default .NET Core application model. e8b8861ac7faf042c87a5c2f9f2d04c98b69f28d When using NuGet 3.x this package requires at least version 3.4.

Library home page: https://api.nuget.org/packages/microsoft.netcore.app.2.0.0.nupkg

Path to dependency file: /NewVoiceMedia.Pci.Integration.csproj

Path to vulnerable library: /ft.netcore.app/2.0.0/microsoft.netcore.app.2.0.0.nupkg

Dependency Hierarchy:

  • microsoft.netcore.app.2.0.0.nupkg (Vulnerable Library)

Found in HEAD commit: 2b41f741fda6b99db25173d55071790a35ab3696

Found in base branch: master

Vulnerability Details

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka '.NET Core & .NET Framework Denial of Service Vulnerability'.

Publish Date: 2020-05-21

URL: CVE-2020-1108

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.1%

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-3w5p-jhp5-c29q

Release Date: 2020-05-21

Fix Resolution: Microsoft.NETCore.App - 2.1.18, Microsoft.NETCore.App.Runtime - 3.1.4

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2018-8416

Vulnerable Library - microsoft.netcore.app.2.0.0.nupkg

A set of .NET API's that are included in the default .NET Core application model. e8b8861ac7faf042c87a5c2f9f2d04c98b69f28d When using NuGet 3.x this package requires at least version 3.4.

Library home page: https://api.nuget.org/packages/microsoft.netcore.app.2.0.0.nupkg

Path to dependency file: /NewVoiceMedia.Pci.Integration.csproj

Path to vulnerable library: /ft.netcore.app/2.0.0/microsoft.netcore.app.2.0.0.nupkg

Dependency Hierarchy:

  • microsoft.netcore.app.2.0.0.nupkg (Vulnerable Library)

Found in HEAD commit: 2b41f741fda6b99db25173d55071790a35ab3696

Found in base branch: master

Vulnerability Details

A tampering vulnerability exists when .NET Core improperly handles specially crafted files, aka ".NET Core Tampering Vulnerability." This affects .NET Core 2.1.

Publish Date: 2018-11-14

URL: CVE-2018-8416

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.1%

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2018-11-14

Fix Resolution: Microsoft.NETCore.App - 2.1.7

⛑️ Automatic Remediation will be attempted for this issue.

CVE-2018-8292

Vulnerable Library - microsoft.netcore.app.2.0.0.nupkg

A set of .NET API's that are included in the default .NET Core application model. e8b8861ac7faf042c87a5c2f9f2d04c98b69f28d When using NuGet 3.x this package requires at least version 3.4.

Library home page: https://api.nuget.org/packages/microsoft.netcore.app.2.0.0.nupkg

Path to dependency file: /NewVoiceMedia.Pci.Integration.csproj

Path to vulnerable library: /ft.netcore.app/2.0.0/microsoft.netcore.app.2.0.0.nupkg

Dependency Hierarchy:

  • microsoft.netcore.app.2.0.0.nupkg (Vulnerable Library)

Found in HEAD commit: 2b41f741fda6b99db25173d55071790a35ab3696

Found in base branch: master

Vulnerability Details

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

Publish Date: 2018-10-10

URL: CVE-2018-8292

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 1.6%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2018-10-10

Fix Resolution: System.Net.Http - 4.3.4;Microsoft.PowerShell.Commands.Utility - 6.1.0-rc.1

⛑️ Automatic Remediation will be attempted for this issue.


⛑️Automatic Remediation will be attempted for this issue.

@mend-for-github-com mend-for-github-com bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Aug 4, 2022
@mend-for-github-com mend-for-github-com bot changed the title microsoft.netcore.app.2.0.0.nupkg: 2 vulnerabilities (highest severity is: 7.5) microsoft.netcore.app.2.0.0.nupkg: 3 vulnerabilities (highest severity is: 7.5) Oct 25, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

No branches or pull requests

0 participants