{"id":"GHSA-xr8f-59pp-rxxh","summary":"Elevation of privilege in ASP.NET Core","details":"An elevation of privilege vulnerability exists when a ASP.NET Core web application, created using vulnerable project templates, fails to properly sanitize web requests, aka 'ASP.NET Core Elevation Of Privilege Vulnerability'.","aliases":["CVE-2019-1302"],"modified":"2024-12-03T05:52:18.093729Z","published":"2022-05-24T22:00:33Z","database_specific":{"github_reviewed_at":"2022-07-07T23:10:41Z","nvd_published_at":"2019-09-11T22:15:00Z","cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1302"},{"type":"WEB","url":"https://github.com/aspnet/Announcements/issues/384"},{"type":"WEB","url":"https://github.com/github/advisory-database/issues/302"},{"type":"WEB","url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1302"}],"affected":[{"package":{"name":"Microsoft.AspNetCore.SpaServices","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.AspNetCore.SpaServices"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.2.0"},{"fixed":"2.2.7"}]}],"versions":["2.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr8f-59pp-rxxh/GHSA-xr8f-59pp-rxxh.json"}},{"package":{"name":"Microsoft.AspNetCore.SpaServices","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.AspNetCore.SpaServices"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.1.0"},{"fixed":"2.1.13"}]}],"versions":["2.1.0","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-xr8f-59pp-rxxh/GHSA-xr8f-59pp-rxxh.json"}}],"schema_version":"1.9.0"}