Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It sounds like this is anything built upon Kestrel which is a lot. I was going to try to list it all here, but holy cow.


ASP.NET Core:

>= 6.0.0 <= 6.0.36

>= 8.0.0 <= 8.0.20

>= 9.0.0 <= 9.0.9

<= 10.0.0-rc.1

Microsoft.AspNetCore.Server.Kestrel.Core:

<= 2.3.0


Those are just the ones they're fixing. Versions <6.0 are still vulnerable, they're just not getting patched because they're out of support.


Don't use out of support software or at least don't use out of support software exposed to the internet.


Internal attacks are easy enough in a large enough network.


>= 6.0.0 <= 6.0.36 versions are not being fixed by Microsoft.

Fixes are available for .NET 6 from HeroDevs ongoing security support for .NET 6, called NES* for .NET.

*never ending support


7 is also EOL. It did not receive a patch. Last time it was updated was May 2024




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: