Vulnerability Database

Search the MergeBase vulnerability database for information on known vulnerabilities in open-source components.

Risk Score
risk image
7.5
Out of 10
Summary
CWEs
Published
2018-09-13
Updated
2022-10-04
Source
NVD
Identifier

CVE-2018-8409

Description
A denial of service vulnerability exists when System.IO.Pipelines improperly handles requests, aka "System.IO.Pipelines Denial of Service." This affects .NET Core 2.1, System.IO.Pipelines, ASP.NET Core 2.1.
MergeBase Comment
This vulnerability affects dotnet as a language generally, and the Sytem.IO.Pipelines package specifically. Any software that uses this package, and who is running on a system whose .NET Core SDK version is less than 2.1.402 or whose highest Microsoft.AspNetCore.App runtime version is less that 2.1.4 is vulnerable to this issue. You can check this by running dotnet --info. This vulnerability makes affected software using the System.IO.Pipeline package weak to remote unauthenticated exploiters who provide particular web requests to said application. Microsoft suggests the following: "To update ASP.NET Core 2.1 you should download and install the .NET Core SDK 2.1.402 on your development machines and build servers, and the .NET Core Runtime 2.1.4 on your deployment servers. Your application will roll forward to these versions on an application restart."
Common Weakness Enumeration (CWE)

Discover More from MergeBase

Open Source Protection

Stay on top of the real risk of open source at any time.

Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility, and popularity.

More on Continuous Protection

Add Dynamic Application Surveillance and Hardening

Detect and defend against known-vulnerabilities at runtime. The only SCA to do so.

The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.

More on Runtime

Shift Left Now

MergeBase directly integrates with Github and Bitbucket to provide an early warning system for your in-house development

Product Overview