CVE-2021-1723: ASP.NET Core and Visual Studio Denial of Service Vulnerability
A denial-of-service vulnerability exists in the way Kestrel parses HTTP/2 requests. The security update addresses the vulnerability by fixing the way the Kestrel parses HTTP/2 requests. Users are advised to upgrade.
Other sources
ASP.NET Core and Visual Studio Denial of Service Vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-1723?
CVE-2021-1723 is a Denial of Service vulnerability in ASP.NET Core and Visual Studio.
What is the severity of CVE-2021-1723?
CVE-2021-1723 has a severity of 7.5 (high).
Which software products are affected by CVE-2021-1723?
ASP.NET Core versions 3.1 to 3.1.10, 5.0 to 5.0.1, and Microsoft Visual Studio 2019 versions 16.0 to 16.8 are affected.
How can I fix CVE-2021-1723?
Apply the necessary updates or patches provided by Microsoft or Fedora Project, depending on the affected software.
Where can I find more information about CVE-2021-1723?
You can find more information about CVE-2021-1723 at the following reference: [link](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1723)