Skip to content

ASP.NET Core Denial of Service Vulnerability

Critical
rbhanda published GHSA-mcwm-2wmc-6hv4 Jun 8, 2021

Package

aspnetcorev2_inprocess.dll (binary)

Affected versions

<13.1.21133.15 <15.0.21133.6

Patched versions

13.1.21133.16 15.0.21133.7

Description

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0 and .NET Core 3.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

A denial of service vulnerability exists when ASP.NET Core improperly handles client disconnect. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication.

Patches

Other Details

Severity

Critical

CVE ID

CVE-2021-31957

Weaknesses

No CWEs