CVE-2018-8409: High severity microsoft .net core runtime vulnerability
Published Sep 13, 2018
·Updated
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
Affected Software
3 affected components
Microsoft .NET Core>=2.1<2.1.4
Microsoft ASP.NET Core>=2.1<2.1.4
Microsoft System.io.pipelines=4.5.0
Remediation
Event History
Sep 13, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-8409.
2
What is the severity of CVE-2018-8409?
The severity of CVE-2018-8409 is high with a CVSS score of 7.5.
3
What is the affected software?
The affected software includes .NET Core 2.1, ASP.NET Core 2.1, and Microsoft System.IO.Pipelines 4.5.0.
4
What is the description of CVE-2018-8409?
CVE-2018-8409 is a denial of service vulnerability that exists when System.IO.Pipelines improperly handles requests.
5
How can I fix CVE-2018-8409?
To fix CVE-2018-8409, users should update to a version above 2.1.4 for .NET Core and ASP.NET Core, or update to a version higher than 4.5.0 for Microsoft System.IO.Pipelines.