July 14th, 2020

.NET Core July 2020 Updates – 2.1.20 and 3.1.6

Rahul Bhandari (MSFT)
Senior Program Manager

Today, we are releasing the .NET Core July 2020 Update. These updates contain security and reliability fixes. See the individual release notes for details on updated packages.

Security

CVE-2020-1147: .NET Core Remote Code Execution Vulnerability

Microsoft is releasing this security advisory to provide information about a vulnerability in .NET Core. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.

Microsoft is aware of a remote code execution vulnerability exists in .NET software when the software fails to check the source markup of an XML file. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user.

A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to an ASP.NET Core application, or other application that parses certain types of XML.

The security update addresses the vulnerability by restricting the types that are allowed to be present in the XML payload

Getting the Update

See the .NET Core release notes for details on the release, including issues fixed and affected packages. 

The latest .NET Core updates are available on the .NET Core download page.

Docker Images

.NET Docker images have been updated for today’s release. The following repos have been updated.

Note: You must pull updated .NET Core container images to get this update, with either docker pull or docker build --pull.

Visual Studio 

This update will be included in a future update of Visual Studio. 

Each version of Visual studio is only supported with a given version of the .NET Core SDK. Visual Studio version information is included in the .NET Core SDK download pages and release notes. If you are not using Visual Studio, we recommend using the latest SDK release. 

 

Category
.NET

Author

Rahul Bhandari (MSFT)
Senior Program Manager

I am a Program Manager on .NET team. I specializes in .NET release processes. University of Florida Alumnus.

1 comment

Discussion is closed. Login to edit/delete existing comments.

  • Kirsan

    Why in release notes no one word about WinForms fixes?