Open mend-bolt-for-github[bot] opened 2 years ago
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
:heavy_check_mark: This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
:information_source: This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Vulnerable Library - microsoft.aspnetcore.mvc.1.1.4.nupkg
Path to dependency file: /src/AzureIntegration/test/Microsoft.AspNetCore.AzureAppServices.FunctionalTests/Assets/Legacy.1.1.3.mvc.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.mvc.core/1.1.4/microsoft.aspnetcore.mvc.core.1.1.4.nupkg
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2017-8700
### Vulnerable Libraries - microsoft.aspnetcore.mvc.cors.1.1.4.nupkg, microsoft.aspnetcore.mvc.core.1.1.4.nupkg### microsoft.aspnetcore.mvc.cors.1.1.4.nupkg
ASP.NET Core MVC cross-origin resource sharing (CORS) features.
Library home page: https://api.nuget.org/packages/microsoft.aspnetcore.mvc.cors.1.1.4.nupkg
Path to dependency file: /src/AzureIntegration/test/Microsoft.AspNetCore.AzureAppServices.FunctionalTests/Assets/Legacy.1.1.3.mvc.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.mvc.cors/1.1.4/microsoft.aspnetcore.mvc.cors.1.1.4.nupkg
Dependency Hierarchy: - microsoft.aspnetcore.mvc.1.1.4.nupkg (Root Library) - :x: **microsoft.aspnetcore.mvc.cors.1.1.4.nupkg** (Vulnerable Library) ### microsoft.aspnetcore.mvc.core.1.1.4.nupkg
ASP.NET Core MVC core components. Contains common action result types, attribute routing, applicatio...
Library home page: https://api.nuget.org/packages/microsoft.aspnetcore.mvc.core.1.1.4.nupkg
Path to dependency file: /src/AzureIntegration/test/Microsoft.AspNetCore.AzureAppServices.FunctionalTests/Assets/Legacy.1.1.3.mvc.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.mvc.core/1.1.4/microsoft.aspnetcore.mvc.core.1.1.4.nupkg
Dependency Hierarchy: - microsoft.aspnetcore.mvc.1.1.4.nupkg (Root Library) - microsoft.aspnetcore.mvc.viewfeatures.1.1.4.nupkg - :x: **microsoft.aspnetcore.mvc.core.1.1.4.nupkg** (Vulnerable Library)
Found in HEAD commit: e512408cb0b9fc17164d22b08f507d2e41131490
Found in base branch: main
### Vulnerability DetailsASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".
Publish Date: 2017-11-15
URL: CVE-2017-8700
### CVSS 3 Score Details (7.5)Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: None
For more information on CVSS3 Scores, click here. ### Suggested FixType: Upgrade version
Origin: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8700
Release Date: 2017-11-15
Fix Resolution: Microsoft.AspNetCore - 1.2; Microsoft.AspNetCore.Mvc.Core - 1.0.6, 1.1.6; Microsoft.AspNetCore.Mvc.Cors - 1.0.6, 1.1.6
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)