A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asp.net_model_view_controller | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Asp.net_model_view_controller | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Asp.net_model_view_controller | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Asp.net_model_view_controller | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Asp.net_model_view_controller | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Asp.net_model_view_controller | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Asp.net_model_view_controller | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.abstractions | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.apiexplorer | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.cors | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.dataannotations | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.formatters.json | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.formatters.xml | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.localization | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.razor | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.razor.host | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.taghelpers | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.viewfeatures | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.0.0 (including) | 1.0.0 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.0.1 (including) | 1.0.1 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.0.2 (including) | 1.0.2 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.0.3 (including) | 1.0.3 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.1.0 (including) | 1.1.0 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.1.1 (including) | 1.1.1 (including) |
Microsoft.aspnetcore.mvc.webapicompatshim | Microsoft | 1.1.2 (including) | 1.1.2 (including) |
System.net.http | Microsoft | 4.1.1 (including) | 4.1.1 (including) |
System.net.http | Microsoft | 4.3.1 (including) | 4.3.1 (including) |
System.net.http.winhttphandler | Microsoft | 4.0.1 (including) | 4.0.1 (including) |
System.net.http.winhttphandler | Microsoft | 4.3.0 (including) | 4.3.0 (including) |
System.net.security | Microsoft | 4.0.0 (including) | 4.0.0 (including) |
System.net.security | Microsoft | 4.3.0 (including) | 4.3.0 (including) |
System.net.websockets.client | Microsoft | 4.0.0 (including) | 4.0.0 (including) |
System.net.websockets.client | Microsoft | 4.3.0 (including) | 4.3.0 (including) |
System.text.encodings.web | Microsoft | 4.0.0 (including) | 4.0.0 (including) |
System.text.encodings.web | Microsoft | 4.3.0 (including) | 4.3.0 (including) |
Input validation is a frequently-used technique for checking potentially dangerous inputs in order to ensure that the inputs are safe for processing within the code, or when communicating with other components. Input can consist of:
Data can be simple or structured. Structured data can be composed of many nested layers, composed of combinations of metadata and raw data, with other simple or structured data. Many properties of raw data or metadata may need to be validated upon entry into the code, such as:
Implied or derived properties of data must often be calculated or inferred by the code itself. Errors in deriving properties may be considered a contributing factor to improper input validation.