Domain-Spoofing The advisory has been revoked - it doesn't affect any version of package microsoft.netcore.app Open this link in a new tab
Threat Intelligence
EPSS
0.28% (68th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DOTNET-MICROSOFTNETCOREAPP-173690
- published 14 Feb 2019
- disclosed 12 Feb 2019
- credit Unknown
Introduced: 12 Feb 2019
CVE-2019-0657 Open this link in a new tabAmendment
This was deemed not a vulnerability.
Overview
Microsoft.NETCore.App is a set of .NET API's that are included in the default .NET Core application model.
Affected versions of this package are vulnerable to Domain-Spoofing. It causes the meaning of a URI to change when International Domain Name encoding is applied. An attacker who successfully exploited the vulnerability could redirect a URI.