Language-ecosystem packages (from OSV) tied to this CVE, with the version that fixes it - the dependency-level detail NVD doesn’t carry.
NuGet
Microsoft.AspNetCore.Mvc
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Abstractions
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.ApiExplorer
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Core
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Cors
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.DataAnnotations
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Formatters.Json
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Formatters.Xml
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Localization
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Razor
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.Razor.Host
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.TagHelpers
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.ViewFeatures
MODERATE
fixed in 1.0.4
NuGet
Microsoft.AspNetCore.Mvc.WebApiCompatShim
MODERATE
fixed in 1.0.4
NuGet
System.Net.Http
MODERATE
fixed in 4.1.2
NuGet
System.Net.Http.WinHttpHandler
MODERATE
fixed in 4.0.1
NuGet
System.Net.Security
MODERATE
fixed in 4.0.1
NuGet
System.Net.WebSockets.Client
MODERATE
fixed in 4.0.1
NuGet
System.Text.Encodings.Web
MODERATE
fixed in 4.0.1