CVE-2020-0602: High severity asp.net core vulnerability
Published Jan 9, 2020
·Updated
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests, aka 'ASP.NET Core Denial of Service Vulnerability'.
Affected Software
7 affected componentsFixes available
redhat/aspnet core<3.0.1
3.0.1
redhat/aspnet core<3.1.1
3.1.1
Microsoft ASP.NET Core=2.1
Microsoft ASP.NET Core=3.0
Microsoft ASP.NET Core=3.1
redhat Enterprise Linux=8.0
redhat Enterprise Linux Eus=8.1
Remediation
Event History
Jan 14, 2020
CVE Published
via MITRE·11:11 PM
Data Sourced
via MITRE·11:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-0602?
The severity of CVE-2020-0602 is high with a severity value of 7.5.
2
How does the denial of service vulnerability in ASP.NET Core occur?
The denial of service vulnerability in ASP.NET Core occurs due to improper handling of web requests.
3
Which versions of ASP.NET Core are affected by CVE-2020-0602?
ASP.NET Core versions 2.1, 3.0, 3.0.1, and 3.1 are affected by CVE-2020-0602.
4
How can I fix CVE-2020-0602?
To fix CVE-2020-0602, update ASP.NET Core to version 3.0.1 or 3.1.1 depending on the installed version.
5
Where can I find more information about CVE-2020-0602?
More information about CVE-2020-0602 can be found at the following references: - Microsoft Security Guidance Advisory: [link1] - ASP.NET GitHub Announcements: [link2] - Redhat Errata: [link3]