ZeroHour

CVE-2020-1045

CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.

Vendors
microsoftfedoraprojectredhat
Products
asp.net core, fedora, enterprise linux, enterprise linux aus, enterprise linux eus, enterprise linux tus
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.