CVE-2020-1045
—CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.
- Vendors
- microsoftfedoraprojectredhat
- Products
- asp.net core, fedora, enterprise linux, enterprise linux aus, enterprise linux eus, enterprise linux tus
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.