GHSA-59j7-ghrg-fj52
MODERATECVE-2024-21319A Denial of Service vulnerability exists in ASP.NET Core project templates which utilize JWT-based authentication tokens. This vulnerability allows an unauthenticated client to consume arbitrarily large amounts of server memory, potentially triggering an out-of-memory condition on the server and making the server no longer able to respond to legitimate requests.
- Affected
- >= 7.0.0-preview, < 7.1.2, >= 6.5.0, < 6.34.0, < 5.7.0
- Fixed in
- 7.1.2
- Weakness
- CWE-400
- Published
- 2024-01-09
- Source
- github