CVE Vulnerabilities

CVE-2020-1108

Published: May 21, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
root.io logo minimus.io logo echo.ai logo

A denial of service vulnerability exists when .NET Core or .NET Framework improperly handles web requests, aka .NET Core & .NET Framework Denial of Service Vulnerability.

Affected Software

NameVendorStart VersionEnd Version
.netMicrosoft5.0-preview1 (including)5.0-preview1 (including)
.netMicrosoft5.0-preview2 (including)5.0-preview2 (including)
.netMicrosoft5.0-preview3 (including)5.0-preview3 (including)
.net_coreMicrosoft2.1 (including)2.1.18 (including)
.net_coreMicrosoft3.0 (including)3.1.4 (including)
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-0:2.1-17.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-dotnet-0:2.1.514-2.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-0:2.1-18.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet21-dotnet-0:2.1.515-1.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet31-dotnet-0:3.1.104-2.el7*
.NET Core on Red Hat Enterprise LinuxRedHatrh-dotnet31-dotnet-0:3.1.105-1.el7*
Red Hat Enterprise Linux 8RedHatdotnet-0:2.1.514-2.el8_2*
Red Hat Enterprise Linux 8RedHatdotnet3.1-0:3.1.104-2.el8_2*
Red Hat Enterprise Linux 8RedHatdotnet3.1-0:3.1.105-2.el8_2*
Red Hat Enterprise Linux 8RedHatdotnet-0:2.1.515-1.el8_2*

References