High severity8.8NVD Advisory· Published Sep 11, 2019· Updated Jun 17, 2026
CVE-2019-1302
CVE-2019-1302
Description
An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.SpaServicesNuGet | >= 2.2.0, < 2.2.7 | 2.2.7 |
Microsoft.AspNetCore.SpaServicesNuGet | >= 2.1.0, < 2.1.13 | 2.1.13 |
Affected products
5cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:asp.net_core:2.1:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:2.2:*:*:*:*:*:*:*
- cpe:2.3:a:microsoft:asp.net_core:3.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-xr8f-59pp-rxxhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-1302ghsaADVISORY
- github.com/aspnet/Announcements/issues/384ghsaWEB
- github.com/github/advisory-database/issues/302ghsaWEB
News mentions
0No linked articles in our index yet.