Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as control elements or syntactic markers when they are sent to a downstream component.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| .net | Microsoft | 10.0.0 (including) | 10.0.6 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | dotnet10.0-0:10.0.106-1.el10_1 | * |
| Red Hat Enterprise Linux 10 | RedHat | dotnet8.0-0:8.0.126-1.el10_1 | * |
| Red Hat Enterprise Linux 10 | RedHat | dotnet9.0-0:9.0.116-1.el10_1 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | dotnet9.0-0:9.0.116-1.el10_0 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | dotnet8.0-0:8.0.126-1.el10_0 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet8.0-0:8.0.126-1.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet10.0-0:10.0.106-1.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | dotnet9.0-0:9.0.116-1.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet8.0-0:8.0.126-1.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet10.0-0:10.0.106-1.el9_7 | * |
| Red Hat Enterprise Linux 9 | RedHat | dotnet9.0-0:9.0.116-1.el9_7 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | dotnet8.0-0:8.0.126-1.el9_4 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | dotnet9.0-0:9.0.116-1.el9_6 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | dotnet8.0-0:8.0.126-1.el9_6 | * |
| Red Hat Hardened Images | RedHat | dotnet10-0-main-10.0.106-1.hum1 | * |
| Red Hat Hardened Images | RedHat | dotnet8-0-main-8.0.126-1.hum1 | * |
| Red Hat Hardened Images | RedHat | dotnet9-0-main-9.0.116-1.hum1 | * |
| Dotnet10 | Ubuntu | devel | * |
| Dotnet10 | Ubuntu | noble | * |
| Dotnet10 | Ubuntu | questing | * |
| Dotnet10 | Ubuntu | resolute | * |
| Dotnet10 | Ubuntu | upstream | * |
| Dotnet7 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | jammy | * |
| Dotnet8 | Ubuntu | noble | * |
| Dotnet8 | Ubuntu | questing | * |
| Dotnet8 | Ubuntu | upstream | * |
| Dotnet9 | Ubuntu | questing | * |
| Dotnet9 | Ubuntu | upstream | * |