Insecure digital certificates In microsoft.netcore.app
Description
Improper Certificate Validation .NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly parsing certificate data. A denial of service vulnerability exists when .NET Core improperly handles parsing certificate data, aka ".NET CORE Denial Of Service Vulnerability".
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
nuget | 2.0.3 | ||
nuget | 4.1.2 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.