CVE-2019-0548: High severity asp.net core vulnerability
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka "ASP.NET Core Denial of Service Vulnerability." This affects ASP.NET Core 2.2, ASP.NET Core 2.1. This CVE ID is unique from CVE-2019-0564.
Other sources
Today, aborted websocket connections to keep an open connection between ANCM and Kestrel due to a bug with websocket disconnect detection. If continued, internal ports would be exhausted, causing the server to effectively be DDOS’d.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-0548.
What is the severity of CVE-2019-0548?
The severity of CVE-2019-0548 is high with a CVSS score of 7.5.
Which versions of ASP.NET Core are affected by CVE-2019-0548?
ASP.NET Core versions 2.1 and 2.2 are affected by CVE-2019-0548.
How does CVE-2019-0548 impact the affected software?
CVE-2019-0548 allows an attacker to cause a denial of service by exploiting the way ASP.NET Core handles web requests.
Are there any references or additional information available for CVE-2019-0548?
Yes, you can find more information about CVE-2019-0548 in the references provided: [Link 1](https://access.redhat.com/errata/RHSA-2019:0040), [Link 2](https://github.com/aspnet/Announcements/issues/335), [Link 3](https://github.com/aspnet/AspNetCore/issues/6488).