Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-1045
Description:

A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.

The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded.

The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.

Test IDs: 1.3.6.1.4.1.25623.1.0.817388   1.3.6.1.4.1.25623.1.0.878389   1.3.6.1.4.1.25623.1.0.878306   1.3.6.1.4.1.25623.1.0.817387  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-1045
FEDORA-2020-48fa1ad65c
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/
FEDORA-2020-e2deb72e0f
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/
https://access.redhat.com/errata/RHSA-2020:3699
https://access.redhat.com/errata/RHSA-2020:3699
https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318
https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.md#changes-in-318
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045
https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600
https://security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600




© 1998-2025 E-Soft Inc. All rights reserved.