Skip to content

Elevation of privilege in ASP.NET Core

Moderate severity GitHub Reviewed Published May 24, 2022 to the GitHub Advisory Database • Updated Jan 31, 2023

Package

nuget Microsoft.AspNetCore.SpaServices (NuGet)

Affected versions

>= 2.2.0, < 2.2.7
>= 2.1.0, < 2.1.13

Patched versions

2.2.7
2.1.13

Description

An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.

References

Published by the National Vulnerability Database Sep 11, 2019
Published to the GitHub Advisory Database May 24, 2022
Reviewed Jul 7, 2022
Last updated Jan 31, 2023

Severity

Moderate

EPSS score

0.274%
(68th percentile)

Weaknesses

No CWEs

CVE ID

CVE-2019-1302

GHSA ID

GHSA-xr8f-59pp-rxxh

Source code

No known source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.