HIGHNuGet →
Microsoft ASP.NET Core project templates vulnerable to denial of service
Microsoft ASP.NET Core project templates vulnerable to denial of service
Affected packages
- Microsoft.IdentityModel.JsonWebTokens— before 5.7.0
- System.IdentityModel.Tokens.Jwt— before 5.7.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-8g9c-28fc-mcx2
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-59j7-ghrg-fj52
- https://github.com/dotnet/announcements/issues/290
- https://github.com/dotnet/aspnetcore
Structured record: https://osv.dev/vulnerability/GHSA-59j7-ghrg-fj52
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta