Vulnerability Name: | CVE-2020-1045 (CCN-187294) | ||||||||||||||||||
Assigned: | 2019-11-04 | ||||||||||||||||||
Published: | 2020-07-01 | ||||||||||||||||||
Updated: | 2022-12-12 | ||||||||||||||||||
Summary: | A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names., aka 'Microsoft ASP.NET Core Security Feature Bypass Vulnerability'. | ||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
6.5 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||||||||||||
Vulnerability Type: | CWE-807 | ||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-1045 Source: secure@microsoft.com Type: Third Party Advisory secure@microsoft.com Source: XF Type: UNKNOWN ms-dotnet-cve20201045-sec-bypass(187294) Source: secure@microsoft.com Type: Release Notes, Third Party Advisory secure@microsoft.com Source: secure@microsoft.com Type: Mailing List, Third Party Advisory secure@microsoft.com Source: secure@microsoft.com Type: Mailing List, Third Party Advisory secure@microsoft.com Source: CCN Type: Microsoft Security TechCenter - September 2020 Microsoft ASP.NET Core Security Feature Bypass Vulnerability Source: secure@microsoft.com Type: Patch, Vendor Advisory secure@microsoft.com Source: secure@microsoft.com Type: Third Party Advisory secure@microsoft.com Source: CCN Type: IBM Security Bulletin 6579917 (Robotic Process Automation) Multiple Vulnerabilities may affect IBM Robotic Process Automation | ||||||||||||||||||
Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |