CVE-2023-38180
ASP.NET Core Kestrel: failure to disconnect a malicious client causes denial of service
Technology
.NET
CVSS Score
7.5 / 10.0
Affected Versions
.NET 7.0 and 6.0 before the August 2023 releases; ASP.NET Core 2.1 packages
Upstream Fix
7.0.10; 6.0.21
Published
August 8, 2023
OSSeva Coverage
Fixed upstream
Description
On detecting a potentially malicious client, Kestrel sometimes failed to disconnect it, resulting in denial of service. CISA added the CVE to its Known Exploited Vulnerabilities catalogue on 9 August 2023. Microsoft notes that a reverse proxy or web application firewall with its own HTTP mitigations may mitigate it. CVSS is Microsoft's score as the CNA.
Is your .NET deployment affected?
If you're running .NET 7.0 and 6.0 before the August 2023 releases; ASP.NET Core 2.1 packages, you need this patch. Book a discovery call to get covered.