Skip to content

CVE-2021-26701 (High) detected in system.text.encodings.web.4.5.0.nupkg #21

@mend-bolt-for-github

Description

@mend-bolt-for-github

CVE-2021-26701 - High Severity Vulnerability

Vulnerable Library - system.text.encodings.web.4.5.0.nupkg

Provides types for encoding and escaping strings for use in JavaScript, HyperText Markup Language (H...

Library home page: https://api.nuget.org/packages/system.text.encodings.web.4.5.0.nupkg

Path to dependency file: /tmp/ws-scm/MyJohnDeereAPI-OAuth2-CSharp-Example/CSharpApp/CSharpApp.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/system.text.encodings.web/4.5.0/system.text.encodings.web.4.5.0.nupkg

Dependency Hierarchy:

  • microsoft.visualstudio.web.codegeneration.design.3.0.0.nupkg (Root Library)
    • microsoft.visualstudio.web.codegenerators.mvc.3.0.0.nupkg
      • microsoft.visualstudio.web.codegeneration.3.0.0.nupkg
        • microsoft.visualstudio.web.codegeneration.entityframeworkcore.3.0.0.nupkg
          • microsoft.visualstudio.web.codegeneration.core.3.0.0.nupkg
            • microsoft.visualstudio.web.codegeneration.templating.3.0.0.nupkg
              • microsoft.aspnetcore.razor.runtime.2.2.0.nupkg
                • microsoft.aspnetcore.html.abstractions.2.2.0.nupkg
                  • system.text.encodings.web.4.5.0.nupkg (Vulnerable Library)

Found in base branch: master

Vulnerability Details

.NET Core Remote Code Execution Vulnerability

Publish Date: 2021-02-25

URL: CVE-2021-26701

CVSS 3 Score Details (8.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: High
    • Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2021-02-25

Fix Resolution: System.Text.Encodings.Web - 4.5.1,4.7.2,5.0.1


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions