PT-2020-19793 · I18N · I18N

·

CVE-2020-7791

·

Published

2020-12-11

·

Updated

2022-09-02

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions i18n versions prior to 2.1.15
Description The issue arises from insufficient handling of erroneous language tags in the files src/i18n/Concrete/TextLocalizer.cs and src/i18n/LocalizedApplication.cs. This results in a vulnerability that affects the package i18n.
Recommendations For versions prior to 2.1.15, update to version 2.1.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the TextLocalizer.cs and LocalizedApplication.cs files until a patch is applied. Avoid using erroneous language tags in the affected files to minimize the risk of exploitation.

Fix

RCE

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7791
GHSA-HFVC-G252-RP4G
SNYK-DOTNET-I18N-1050179

Affected Products

I18N