PT-2019-2167 · Microsoft+2 · Net Core+3

Published

2019-05-14

·

Updated

2023-02-02

·

CVE-2019-0820

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions .NET Core and Microsoft .NET Framework (affected versions not specified)
Description The issue is related to errors in processing regular expressions. It could allow a remote attacker to cause a denial of service. A remote unauthenticated attacker could exploit this by issuing specially crafted requests to a .NET Framework or .NET Core application.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01933
CESA-2019_1259
CVE-2019-0820
GHSA-CMHX-CQ75-C4MJ
RHSA-2019:1236
RHSA-2019:1259
RHSA-2019_1259

Affected Products

.Net Framework
Centos
Net Core
Red Hat