PT-2020-19793 · I18N · I18N

Chris Stephens

·

Published

2020-12-11

·

Updated

2022-09-02

·

CVE-2020-7791

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions i18n versions prior to 2.1.15
Description The issue arises from insufficient handling of erroneous language tags in the files src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs. This results in a vulnerability that affects the package i18n.
Recommendations For versions prior to 2.1.15, update to version 2.1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the TextLocalizer.cs and LocalizedApplication.cs files until a patch is applied. Avoid using erroneous language tags in the affected files to minimize the risk of exploitation.

Fix

RCE

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2020-7791
GHSA-HFVC-G252-RP4G
SNYK-DOTNET-I18N-1050179

Affected Products

I18N