Input validation error in ASP.NET Core MVC and Microsoft .NET Core - CVE-2021-24112

 

Input validation error in ASP.NET Core MVC and Microsoft .NET Core - CVE-2021-24112

Published: February 9, 2021


Vulnerability identifier: #VU50495
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24112
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input in .NET Core. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.


Affected software

ASP.NET Core MVC
Microsoft .NET Core
Arch Linux
Anolis OS
Fedora
MySQL Connectors
Oracle Hyperion Data Relationship Management
IBM Robotic Process Automation
dotnet-host-fxr-2.1
dotnet-runtime-2.1
dotnet-sdk-2.1
dotnet-sdk-2.1.5xx
dotnet-targeting-pack-3.1
aspnetcore-runtime-3.1
aspnetcore-targeting-pack-3.1
dotnet-apphost-pack-3.1
dotnet-hostfxr-3.1
dotnet-runtime-3.1
dotnet3.1
dotnet-templates-3.1
dotnet-sdk-3.1-source-built-artifacts
dotnet-sdk-3.1
dotnet5.0

How to mitigate CVE-2021-24112

Install updates from vendor's website.

dotnet-host-fxr-2.1 - update to 2.1.30-1
dotnet-runtime-2.1 - update to 2.1.30-1
dotnet-sdk-2.1 - update to 2.1.526-1
dotnet-sdk-2.1.5xx - update to 2.1.526-1
dotnet-targeting-pack-3.1 - update to 3.1.26-1.0.1
aspnetcore-runtime-3.1 - update to 3.1.26-1.0.1
aspnetcore-targeting-pack-3.1 - update to 3.1.26-1.0.1
dotnet-apphost-pack-3.1 - update to 3.1.26-1.0.1
dotnet-hostfxr-3.1 - update to 3.1.26-1.0.1
dotnet-runtime-3.1 - update to 3.1.26-1.0.1
dotnet3.1 - addressed in versions 3.1.112-1.fc32, 3.1.112-1.fc33
dotnet-templates-3.1 - update to 3.1.420-1.0.1
dotnet-sdk-3.1-source-built-artifacts - update to 3.1.420-1.0.1
dotnet-sdk-3.1 - update to 3.1.420-1.0.1
dotnet5.0 - addressed in versions 5.0.103-1.fc32, 5.0.103-1.fc33
IBM Robotic Process Automation - update to 21.0.7

External References

Related Security Bulletins