CVE-2024-21319
Description
RHSA-2024:0158: .NET 6.0 security update (Important)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description dotnet: .NET Denial of Service Vulnerability Red Hat statement This DoS vulnerability in .NET Core project templates utilizing JWT-based authentication tokens is considered a moderate issue due to its restricted impact. While unauthenticated clients can exploit the server's memory, potentially causing an out-of-memory condition and service disruption, the vulnerability does not leadβ¦
Description
dotnet: .NET Denial of Service Vulnerability
Red Hat statement
This DoS vulnerability in .NET Core project templates utilizing JWT-based authentication tokens is considered a moderate issue due to its restricted impact. While unauthenticated clients can exploit the server's memory, potentially causing an out-of-memory condition and service disruption, the vulnerability does not lead to remote code execution or compromise sensitive data. Its exploitability is contingent on specific project configurations, limiting the scope of affected systems.
CVSS v3: 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet60-dotnet-0:6.0.126-1.el7_9 | RHSA-2024:0255 | 2024-01-15T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet8.0-0:8.0.101-1.el8_9 | RHSA-2024:0150 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet7.0-0:7.0.115-1.el8_9 | RHSA-2024:0157 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 8 | dotnet6.0-0:6.0.126-1.el8_9 | RHSA-2024:0158 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet7.0-0:7.0.115-1.el9_3 | RHSA-2024:0151 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet8.0-0:8.0.101-1.el9_3 | RHSA-2024:0152 | 2024-01-10T00:00:00Z |
| Red Hat Enterprise Linux 9 | dotnet6.0-0:6.0.126-1.el9_3 | RHSA-2024:0156 | 2024-01-10T00:00:00Z |
Apply commands
yum update -y rh-dotnet60-dotnet
# or:
dnf upgrade -y rh-dotnet60-dotnet
OS impact
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | dotnet-sdk-8.0-8.0.101-1.el9_3.aarch64.rpm |
Red Hat Fixed 2 releases
| Version | Status | Fixed in |
|---|---|---|
| 9 | Fixed | β |
| 8 | Fixed | β |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| NuGet | System.IdentityModel.Tokens.Jwt | <5.7.0 | 5.7.0 |
| NuGet | System.IdentityModel.Tokens.Jwt | >=6.5.0,<6.34.0 | 6.34.0 |
| NuGet | System.IdentityModel.Tokens.Jwt | >=7.0.0-preview,<7.1.2 | 7.1.2 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | <5.7.0 | 5.7.0 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | >=6.5.0,<6.34.0 | 6.34.0 |
| NuGet | Microsoft.IdentityModel.JsonWebTokens | >=7.0.0-preview,<7.1.2 | 7.1.2 |
References
- https://access.redhat.com/errata/RHSA-2024:0151
- https://access.redhat.com/errata/RHSA-2024:0152
- https://access.redhat.com/errata/RHSA-2024:0156
- https://errata.rockylinux.org/RLSA-2024:0158
- https://errata.rockylinux.org/RLSA-2024:0150
- https://errata.rockylinux.org/RLSA-2024:0157
- https://github.com/AzureAD/azure-activedirectory-identitymodel-extensions-for-dotnet/security/advisories/GHSA-8g9c-28fc-mcx2
- https://github.com/dotnet/aspnetcore/security/advisories/GHSA-59j7-ghrg-fj52
- https://github.com/dotnet/announcements/issues/290
- https://github.com/dotnet/aspnetcore
- https://access.redhat.com/errata/RHSA-2024:0150
- https://bugzilla.redhat.com/2255384
- https://bugzilla.redhat.com/2255386
- https://bugzilla.redhat.com/2257566
- https://errata.almalinux.org/8/ALSA-2024-0150.html
- https://access.redhat.com/errata/RHSA-2024:0157
- https://errata.almalinux.org/8/ALSA-2024-0157.html
- https://access.redhat.com/errata/RHSA-2024:0158
- https://errata.almalinux.org/8/ALSA-2024-0158.html
- https://errata.almalinux.org/9/ALSA-2024-0151.html
- https://errata.almalinux.org/9/ALSA-2024-0152.html
- https://errata.almalinux.org/9/ALSA-2024-0156.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.