High severity7.5NVD Advisory· Published Sep 11, 2020· Updated Jun 17, 2026
CVE-2020-1045
CVE-2020-1045
Description
A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names. The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker to set a second cookie with the name being percent encoded. The security update addresses the vulnerability by fixing the way the ASP.NET Core cookie parser handles encoded names.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.AspNetCore.HttpNuGet | < 2.1.22 | 2.1.22 |
Microsoft.AspNetCore.AppNuGet | < 2.1.22 | 2.1.22 |
Microsoft.OwinNuGet | < 4.1.1 | 4.1.1 |
Microsoft.AspNetCore.App.Runtime.linux-armNuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.linux-arm64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.linux-musl-x64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.linux-x64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.osx-x64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.win-armNuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.win-x64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.win-x86NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.linux-musl-arm64NuGet | >= 3.1.0, < 3.1.8 | 3.1.8 |
Microsoft.AspNetCore.App.Runtime.win-arm64NuGet | >= 3.1.5, < 3.1.8 | 3.1.8 |
Affected products
29- osv-coords14 versionspkg:bitnami/aspnet-corepkg:nuget/microsoft.aspnetcore.httppkg:nuget/microsoft.aspnetcore.apppkg:nuget/microsoft.owinpkg:nuget/microsoft.aspnetcore.app.runtime.linux-armpkg:nuget/microsoft.aspnetcore.app.runtime.linux-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-x64pkg:nuget/microsoft.aspnetcore.app.runtime.linux-x64pkg:nuget/microsoft.aspnetcore.app.runtime.osx-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-armpkg:nuget/microsoft.aspnetcore.app.runtime.win-x64pkg:nuget/microsoft.aspnetcore.app.runtime.win-x86pkg:nuget/microsoft.aspnetcore.app.runtime.linux-musl-arm64pkg:nuget/microsoft.aspnetcore.app.runtime.win-arm64
>= 3.1.0, < 3.1.8+ 13 more
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: < 2.1.22
- (no CPE)range: < 2.1.22
- (no CPE)range: < 4.1.1
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.0, < 3.1.8
- (no CPE)range: >= 3.1.5, < 3.1.8
cpe:2.3:a:microsoft:asp.net_core:2.1*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:microsoft:asp.net_core:2.1*:*:*:*:*:*:*:*range: 2.0
- cpe:2.3:a:microsoft:asp.net_core:3.1:*:*:*:*:*:*:*range: 3.0
- cpe:2.3:a:microsoft:asp.net_core:*:*:*:*:*:*:*:*range: >=2.1,<=2.1.21
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_aus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_aus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_aus:8.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_tus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_tus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_tus:8.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
17- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1045nvdPatchVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:3699nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-hxrm-9w7p-39ccghsaADVISORY
- github.com/dotnet/core/blob/main/release-notes/3.1/3.1.8/3.1.8.mdnvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-1045ghsaADVISORY
- security.snyk.io/vuln/SNYK-RHEL8-DOTNET-1439600nvdThird Party AdvisoryWEB
- github.com/dotnet/announcements/issues/165ghsaWEB
- github.com/dotnet/aspnetcore/issues/25701ghsaWEB
- github.com/dotnet/aspnetcore/issues/25701ghsaWEB
- github.com/dotnet/aspnetcore/pull/24264ghsaWEB
- github.com/github/advisory-database/issues/302ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPBghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPBghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LN2FUVBSVPGK7AU3NMLO3YR6CGONQPB/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ASICXQXS4M7MTAF6SGQMCLCA63DLCUT3/nvd
News mentions
0No linked articles in our index yet.