USN-6480-1
Dashboard / Vulnerabilities / USN-6480-1
USN-6480-1
Summary: dotnet6, dotnet7, dotnet8 vulnerabilities
Details: Barry Dorrans discovered that .NET did not properly implement certain security features for Blazor server forms. An attacker could possibly use this issue to bypass validation, which could trigger unintended actions. (CVE-2023-36558) Piotr Bazydlo discovered that .NET did not properly handle untrusted URIs provided to System.Net.WebRequest.Create. An attacker could possibly use this issue to inject arbitrary commands to backend FTP servers. (CVE-2023-36049)
References: https://ubuntu.com/security/notices/USN-6480-1, https://ubuntu.com/security/CVE-2023-36049, https://ubuntu.com/security/CVE-2023-36558
Affected packages
Package
Name: dotnet6
Purl: pkg:deb/ubuntu/[email protected]~22.04.1?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
