CVE-2019-1075Medium

ASP.NET Core Spoofing Vulnerability

Published
July 9, 2019
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

A spoofing vulnerability exists in ASP.NET Core that could lead to an open redirect. An attacker who successfully exploited the vulnerability could redirect a targeted user to a malicious website. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL, and convince the user to click the link. The update addresses the vulnerability by correcting how ASP.NET Core parses URLs.

🎯 Affected products2

  • ASP.NET Core 2.1
  • ASP.NET Core 2.2

✅ Remediation

KBRelease Notes (Security Update)

🔗 References (3)