Open mend-bolt-for-github[bot] opened 2 years ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Vulnerable Library - system.net.http.winhttphandler.4.5.3.nupkg
Provides a message handler for HttpClient based on the WinHTTP interface of Windows. While similar t...
Library home page: https://api.nuget.org/packages/system.net.http.winhttphandler.4.5.3.nupkg
Path to dependency file: /src/Servers/HttpSys/test/FunctionalTests/Microsoft.AspNetCore.Server.HttpSys.FunctionalTests.csproj
Path to vulnerable library: /ages/system.net.http.winhttphandler/4.5.3/system.net.http.winhttphandler.4.5.3.nupkg
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2017-0247
### Vulnerable Library - system.net.http.winhttphandler.4.5.3.nupkgProvides a message handler for HttpClient based on the WinHTTP interface of Windows. While similar t...
Library home page: https://api.nuget.org/packages/system.net.http.winhttphandler.4.5.3.nupkg
Path to dependency file: /src/Servers/HttpSys/test/FunctionalTests/Microsoft.AspNetCore.Server.HttpSys.FunctionalTests.csproj
Path to vulnerable library: /ages/system.net.http.winhttphandler/4.5.3/system.net.http.winhttphandler.4.5.3.nupkg
Dependency Hierarchy: - :x: **system.net.http.winhttphandler.4.5.3.nupkg** (Vulnerable Library)
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Found in base branch: main
### Vulnerability DetailsA denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.
Publish Date: 2017-05-12
URL: CVE-2017-0247
### CVSS 3 Score Details (7.5)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: High - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Release Date: 2017-05-12
Fix Resolution: System.Text.Encodings.Web - 4.0.1,4.3.1, System.Net.Http - 4.1.2,4.3.2, System.Net.Http.WinHttpHandler - 4.0.2,4.5.4, System.Net.Security - 4.0.1,4.3.1, System.Net.WebSockets.Client - 4.0.1,4.3.1, Microsoft.AspNetCore.Mvc - 1.0.4,1.1.3,, Microsoft.AspNetCore.Mvc.Core - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Abstractions - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.ApiExplorer - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Cors - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.DataAnnotations - 1.0.4,1.1.3,,Microsoft.AspNetCore.Mvc.Formatters.Json - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Formatters.Xml - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Localization - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Razor.Host - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.Razor 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.TagHelpers - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.ViewFeatures - 1.0.4,1.1.3, Microsoft.AspNetCore.Mvc.WebApiCompatShim - 1.0.4,1.1.3
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)CVE-2017-0249
### Vulnerable Library - system.net.http.winhttphandler.4.5.3.nupkgProvides a message handler for HttpClient based on the WinHTTP interface of Windows. While similar t...
Library home page: https://api.nuget.org/packages/system.net.http.winhttphandler.4.5.3.nupkg
Path to dependency file: /src/Servers/HttpSys/test/FunctionalTests/Microsoft.AspNetCore.Server.HttpSys.FunctionalTests.csproj
Path to vulnerable library: /ages/system.net.http.winhttphandler/4.5.3/system.net.http.winhttphandler.4.5.3.nupkg
Dependency Hierarchy: - :x: **system.net.http.winhttphandler.4.5.3.nupkg** (Vulnerable Library)
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Found in base branch: main
### Vulnerability DetailsAn elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
Publish Date: 2017-05-12
URL: CVE-2017-0249
### CVSS 3 Score Details (7.3)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: Low - Integrity Impact: Low - Availability Impact: Low
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Release Date: 2017-05-12
Fix Resolution: System.Text.Encodings.Web - 4.0.1,4.3.1;System.Net.Http - 4.1.2,4.3.2;System.Net.Http.WinHttpHandler - 4.0.2,4.3.1;System.Net.Security - 4.0.1,4.3.1;System.Net.WebSockets.Client - 4.0.1,4.3.1;Microsoft.AspNetCore.Mvc - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Core - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Abstractions - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.ApiExplorer - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Cors - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.DataAnnotations - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Formatters.Json - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Formatters.Xml - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Localization - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Razor.Host - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Razor - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.TagHelpers - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.ViewFeatures - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.WebApiCompatShim - 1.0.4,1.1.3
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)CVE-2017-0256
### Vulnerable Library - system.net.http.winhttphandler.4.5.3.nupkgProvides a message handler for HttpClient based on the WinHTTP interface of Windows. While similar t...
Library home page: https://api.nuget.org/packages/system.net.http.winhttphandler.4.5.3.nupkg
Path to dependency file: /src/Servers/HttpSys/test/FunctionalTests/Microsoft.AspNetCore.Server.HttpSys.FunctionalTests.csproj
Path to vulnerable library: /ages/system.net.http.winhttphandler/4.5.3/system.net.http.winhttphandler.4.5.3.nupkg
Dependency Hierarchy: - :x: **system.net.http.winhttphandler.4.5.3.nupkg** (Vulnerable Library)
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Found in base branch: main
### Vulnerability DetailsA spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
Publish Date: 2017-05-12
URL: CVE-2017-0256
### CVSS 3 Score Details (5.3)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2017-0256
Release Date: 2017-05-12
Fix Resolution: Microsoft.AspNetCore.Mvc.ApiExplorer - 1.1.3,1.0.4;Microsoft.AspNetCore.Mvc.Abstractions - 1.1.3,1.0.4;Microsoft.AspNetCore.Mvc.Core - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Cors - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.Localization - 1.1.3,1.0.4;System.Net.Http - 4.1.2,4.3.2;Microsoft.AspNetCore.Mvc.Razor - 1.1.3,1.0.4;System.Net.Http.WinHttpHandler - 4.0.2,4.3.0-preview1-24530-04;System.Net.Security - 4.3.0-preview1-24530-04,4.0.1;Microsoft.AspNetCore.Mvc.ViewFeatures - 1.1.3,1.0.4;Microsoft.AspNetCore.Mvc.TagHelpers - 1.0.4,1.1.3;System.Text.Encodings.Web - 4.3.0-preview1-24530-04,4.0.1;Microsoft.AspNetCore.Mvc.Razor.Host - 1.1.3,1.0.4;Microsoft.AspNetCore.Mvc.Formatters.Json - 1.0.4,1.1.3;Microsoft.AspNetCore.Mvc.WebApiCompatShim - 1.0.4,1.1.3;System.Net.WebSockets.Client - 4.3.0-preview1-24530-04,4.0.1;Microsoft.AspNetCore.Mvc.Formatters.Xml - 1.1.3,1.0.4;Microsoft.AspNetCore.Mvc.DataAnnotations - 1.0.4,1.1.3
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)CVE-2017-0248
### Vulnerable Library - system.net.http.winhttphandler.4.5.3.nupkgProvides a message handler for HttpClient based on the WinHTTP interface of Windows. While similar t...
Library home page: https://api.nuget.org/packages/system.net.http.winhttphandler.4.5.3.nupkg
Path to dependency file: /src/Servers/HttpSys/test/FunctionalTests/Microsoft.AspNetCore.Server.HttpSys.FunctionalTests.csproj
Path to vulnerable library: /ages/system.net.http.winhttphandler/4.5.3/system.net.http.winhttphandler.4.5.3.nupkg
Dependency Hierarchy: - :x: **system.net.http.winhttphandler.4.5.3.nupkg** (Vulnerable Library)
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Found in base branch: main
### Vulnerability DetailsMicrosoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka ".NET Security Feature Bypass Vulnerability."
Publish Date: 2017-05-12
URL: CVE-2017-0248
### CVSS 3 Score Details (5.3)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: Low - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Release Date: 2017-05-12
Fix Resolution: System.Text.Encodings.Web - 4.0.1, 4.3.1;System.Net.Http - 4.1.2, 4.3.2;System.Net.Http.WinHttpHandler - 4.0.2, 4.3.1;System.Net.Security - 4.0.1, 4.3.1;System.Net.WebSockets.Client - 4.0.1, 4.3.1;Microsoft.AspNetCore.Mvc - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Core - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Abstractions - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.ApiExplorer - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Cors - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.DataAnnotations - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Formatters.Json - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Formatters.Xml - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Localization - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Razor.Host - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.Razor - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.TagHelpers - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.ViewFeatures - 1.0.4, 1.1.3;Microsoft.AspNetCore.Mvc.WebApiCompatShim - 1.0.4, 1.1.3
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)