Input validation error in ASP.NET Core MVC and Microsoft .NET Core - CVE-2021-24112
Published: February 9, 2021
Vulnerability identifier: #VU50495
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-24112
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to insufficient validation of user-supplied input in .NET Core. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the target system.
Affected software
ASP.NET Core MVC
Microsoft .NET Core
Arch Linux
Anolis OS
Fedora
MySQL Connectors
Oracle Hyperion Data Relationship Management
IBM Robotic Process Automation
dotnet-host-fxr-2.1
dotnet-runtime-2.1
dotnet-sdk-2.1
dotnet-sdk-2.1.5xx
dotnet-targeting-pack-3.1
aspnetcore-runtime-3.1
aspnetcore-targeting-pack-3.1
dotnet-apphost-pack-3.1
dotnet-hostfxr-3.1
dotnet-runtime-3.1
dotnet3.1
dotnet-templates-3.1
dotnet-sdk-3.1-source-built-artifacts
dotnet-sdk-3.1
dotnet5.0
Microsoft .NET Core
Arch Linux
Anolis OS
Fedora
MySQL Connectors
Oracle Hyperion Data Relationship Management
IBM Robotic Process Automation
dotnet-host-fxr-2.1
dotnet-runtime-2.1
dotnet-sdk-2.1
dotnet-sdk-2.1.5xx
dotnet-targeting-pack-3.1
aspnetcore-runtime-3.1
aspnetcore-targeting-pack-3.1
dotnet-apphost-pack-3.1
dotnet-hostfxr-3.1
dotnet-runtime-3.1
dotnet3.1
dotnet-templates-3.1
dotnet-sdk-3.1-source-built-artifacts
dotnet-sdk-3.1
dotnet5.0
How to mitigate CVE-2021-24112
Install updates from vendor's website.
dotnet-host-fxr-2.1 - update to 2.1.30-1
dotnet-runtime-2.1 - update to 2.1.30-1
dotnet-sdk-2.1 - update to 2.1.526-1
dotnet-sdk-2.1.5xx - update to 2.1.526-1
dotnet-targeting-pack-3.1 - update to 3.1.26-1.0.1
aspnetcore-runtime-3.1 - update to 3.1.26-1.0.1
aspnetcore-targeting-pack-3.1 - update to 3.1.26-1.0.1
dotnet-apphost-pack-3.1 - update to 3.1.26-1.0.1
dotnet-hostfxr-3.1 - update to 3.1.26-1.0.1
dotnet-runtime-3.1 - update to 3.1.26-1.0.1
dotnet3.1 - addressed in versions 3.1.112-1.fc32, 3.1.112-1.fc33
dotnet-templates-3.1 - update to 3.1.420-1.0.1
dotnet-sdk-3.1-source-built-artifacts - update to 3.1.420-1.0.1
dotnet-sdk-3.1 - update to 3.1.420-1.0.1
dotnet5.0 - addressed in versions 5.0.103-1.fc32, 5.0.103-1.fc33
IBM Robotic Process Automation - update to 21.0.7
dotnet-runtime-2.1 - update to 2.1.30-1
dotnet-sdk-2.1 - update to 2.1.526-1
dotnet-sdk-2.1.5xx - update to 2.1.526-1
dotnet-targeting-pack-3.1 - update to 3.1.26-1.0.1
aspnetcore-runtime-3.1 - update to 3.1.26-1.0.1
aspnetcore-targeting-pack-3.1 - update to 3.1.26-1.0.1
dotnet-apphost-pack-3.1 - update to 3.1.26-1.0.1
dotnet-hostfxr-3.1 - update to 3.1.26-1.0.1
dotnet-runtime-3.1 - update to 3.1.26-1.0.1
dotnet3.1 - addressed in versions 3.1.112-1.fc32, 3.1.112-1.fc33
dotnet-templates-3.1 - update to 3.1.420-1.0.1
dotnet-sdk-3.1-source-built-artifacts - update to 3.1.420-1.0.1
dotnet-sdk-3.1 - update to 3.1.420-1.0.1
dotnet5.0 - addressed in versions 5.0.103-1.fc32, 5.0.103-1.fc33
IBM Robotic Process Automation - update to 21.0.7
External References
Related Security Bulletins
- Multiple vulnerabilities in Microsoft .NET Core and Visual Studio
- Arch Linux update for dotnet-runtime
- Arch Linux update for dotnet-sdk
- Input validation error in IBM Robotic Process Automation
- Multiple vulnerabilities in MySQL Connectors
- Fedora 33 update for dotnet5.0
- Fedora 32 update for dotnet3.1
- Fedora 33 update for dotnet3.1
- Fedora 32 update for dotnet5.0
- Anolis OS update for dotnet
- Anolis OS update for dotnet3.1
- Input validation error in Oracle Hyperion Data Relationship Management