amccool/AM.Extensions.Logging.ElasticSearch

CVE-2021-26701 (High) detected in system.text.encodings.web.4.5.0.nupkg

Opened this issue · 0 comments

CVE-2021-26701 - High Severity Vulnerability

Vulnerable Library - system.text.encodings.web.4.5.0.nupkg

Provides types for encoding and escaping strings for use in JavaScript, HyperText Markup Language (H...

Library home page: https://api.nuget.org/packages/system.text.encodings.web.4.5.0.nupkg

Path to dependency file: /src/ElasticLogger.Test/ElasticLogger.Test.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.text.encodings.web/4.5.0/system.text.encodings.web.4.5.0.nupkg

Dependency Hierarchy:

  • microsoft.aspnetcore.hosting.abstractions.2.2.0.nupkg (Root Library)
    • microsoft.aspnetcore.http.abstractions.2.2.0.nupkg
      • system.text.encodings.web.4.5.0.nupkg (Vulnerable Library)

Found in HEAD commit: 9d43b5a63dc0bf1c2e718e2546391545d09f1e6d

Found in base branch: master

Vulnerability Details

.NET Core Remote Code Execution Vulnerability

Publish Date: 2021-02-25

URL: CVE-2021-26701

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2021-02-25

Fix Resolution: System.Text.Encodings.Web - 4.5.1,4.7.2,5.0.1


Step up your Open Source Security Game with Mend here