5 ms·
For context around the score https://github.com/dotnet/aspnetcore/issues/64033#issuecomment-3403054914 https://github.com/dotnet/aspnetcore/issues/64033#issueco
by zovin 1y ago
For context around the score https://github.com/dotnet/aspnetcore/issues/64033#issuecomment-3403054914 https://github.com/dotnet/aspnetcore/issues/64033#issuecomme...
- philipwhiuk 1y agoThis is a dumb way of scoring the bug. The bug itself doesn't enable any of those. An app using the library might have that vuln.
- Ekaros 1y agoScore which is based how someone could theoretically use the tool. It might be right, but it also feels so wrong. I would in reality probably rank this issue lower. And in some more properly engineered systems it would have lot less criticality.
- philipwhiuk 1y agoBut: > someone could theoretically use the tool makes every single logic error a 9.9
- MattPalmer1086 1y agoIt's a generic problem with using CVSS to score library vulnerabilities. CVSS is designed around complete systems, so it's totally crap to apply it to libraries. I see a lot of critical (9+) supposed JavaScript "remote code execution with no authentication" CVEs being posted... Right, if you are running it in an NPM server exposed to malicious user input with no authentication. Actually it runs client side in the browser and at best it's a prototype pollution vuln with a much lower score.
- justin66 1y ago> This is a dumb way of scoring the bug. The above is a motto for the entire vulnerability industrial complex.
- Hawxy 1y agoThis appears to be the code change: https://github.com/dotnet/aspnetcore/commit/97a86434195a82fc7e302a4c57d5ec7f885c1ad5 https://github.com/dotnet/aspnetcore/commit/97a86434195a82fc...
- bob1029 1y agoLooks like a line ending problem. RejectsInvalidChunkExtensions seems to be the unit test that covers the actual concern.