microsoft.aspnetcore.server.httpsys.2.0.1.nupkg: 1 vulnerabilities (highest severity is: 7.5) unreachable #8
Labels
Mend: dependency security vulnerability
Security vulnerability detected by Mend
Vulnerable Library - microsoft.aspnetcore.server.httpsys.2.0.1.nupkg
ASP.NET Core HTTP server that uses the Windows HTTP Server API.
Path to dependency file: /dvcsharp-core-api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.server.httpsys/2.0.1/microsoft.aspnetcore.server.httpsys.2.0.1.nupkg
Found in HEAD commit: 21f9b3d8a5499484535381f975f1b15ceb2519a9
Vulnerabilities
Unreachable
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2017-11883
Vulnerable Library - microsoft.aspnetcore.server.httpsys.2.0.1.nupkg
ASP.NET Core HTTP server that uses the Windows HTTP Server API.
Path to dependency file: /dvcsharp-core-api.csproj
Path to vulnerable library: /home/wss-scanner/.nuget/packages/microsoft.aspnetcore.server.httpsys/2.0.1/microsoft.aspnetcore.server.httpsys.2.0.1.nupkg
Dependency Hierarchy:
Found in HEAD commit: 21f9b3d8a5499484535381f975f1b15ceb2519a9
Found in base branch: master
Reachability Analysis
The vulnerable code is unreachable
Vulnerability Details
.NET Core 1.0, 1.1, and 2.0 allow an unauthenticated attacker to remotely cause a denial of service attack against a .NET Core web application by improperly handling web requests, aka ".NET CORE Denial Of Service Vulnerability".
Publish Date: 2017-11-14
URL: CVE-2017-11883
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Release Date: 2017-11-14
Fix Resolution: Microsoft.AspNetCore.Server.WebListener - 1.0.6,1.1.4;Microsoft.Net.Http.Server - 1.0.6,1.1.4;Microsoft.AspNetCore.Server.HttpSys - 2.0.2
In order to enable automatic remediation, please create workflow rules
In order to enable automatic remediation for this issue, please create workflow rules
The text was updated successfully, but these errors were encountered: