CVE-2019-0545 (High) detected in microsoft.netcore.app.2.1.0.nupkg, microsoft.netcore.app.2.2.0.nupkg

#196 · open · 0 comments

View on GitHub ↗

mend-bolt-for-github[bot]

## CVE-2019-0545 - High Severity Vulnerability <details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/vulnerability_details.png' width=19 height=20> Vulnerable Libraries - <b>microsoft.netcore.app.2.1.0.nupkg</b>, <b>microsoft.netcore.app.2.2.0.nupkg</b></p></summary> <p> <details><summary><b>microsoft.netcore.app.2.1.0.nupkg</b></p></summary> <p>A set of .NET API's that are included in the default .NET Core application model. caa7b7e2bad98e56a687fb5cbaf60825500800f7 When using NuGet 3.x this package requires at least version 3.4.</p> <p>Library home page: <a href="https://api.nuget.org/packages/microsoft.netcore.app.2.1.0.nupkg">https://api.nuget.org/packages/microsoft.netcore.app.2.1.0.nupkg</a></p> <p>Path to dependency file: /Ghpr.ConsoleAppForDebug/Ghpr.ConsoleAppForDebug.csproj</p> <p>Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.netcore.app/2.1.0/microsoft.netcore.app.2.1.0.nupkg</p> <p> Dependency Hierarchy: - :x: **microsoft.netcore.app.2.1.0.nupkg** (Vulnerable Library) </details> <details><summary><b>microsoft.netcore.app.2.2.0.nupkg</b></p></summary> <p>A set of .NET API's that are included in the default .NET Core application model. 1249f08feda72b116...</p> <p>Library home page: <a href="https://api.nuget.org/packages/microsoft.netcore.app.2.2.0.nupkg">https://api.nuget.org/packages/microsoft.netcore.app.2.2.0.nupkg</a></p> <p>Path to dependency file: /Ghpr.SimpleFileLogger.Core/Ghpr.SimpleFileLogger.csproj</p> <p>Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.netcore.app/2.2.0/microsoft.netcore.app.2.2.0.nupkg</p> <p> Dependency Hierarchy: - :x: **microsoft.netcore.app.2.2.0.nupkg** (Vulnerable Library) </details> <p>Found in HEAD commit: <a href="https://github.com/GHPReporter/Ghpr.Core/commit/61c01ea44f52cf09332bbf411ffeb7479870bc5c">61c01ea44f52cf09332bbf411ffeb7479870bc5c</a></p> <p>Found in base branch: <b>master</b></p> </p> </details> <p></p> <details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/high_vul.png?' width=19 height=20> Vulnerability Details</summary> <p> An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2. <p>Publish Date: 2019-01-08 <p>URL: <a href=https://www.mend.io/vulnerability-database/CVE-2019-0545>CVE-2019-0545</a></p> </p> </details> <p></p> <details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/cvss3.png' width=19 height=20> CVSS 3 Score Details (<b>7.5</b>)</summary> <p> Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: High - Integrity Impact: None - Availability Impact: None </p> For more information on CVSS3 Scores, click <a href="https://www.first.org/cvss/calculator/3.0">here</a>. </p> </details> <p></p> <details><summary><img src='https://whitesource-resources.whitesourcesoftware.com/suggested_fix.png' width=19 height=20> Suggested Fix</summary> <p> <p>Type: Upgrade version</p> <p>Release Date: 2019-01-14</p> <p>Fix Resolution: Microsoft.NETCore.App - 2.1.7,2.2.1</p> </p> </details> <p></p> *** Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Comments