Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2017-11879

Опубликовано: 14 нояб. 2017
Источник: msrc
EPSS Низкий

Описание

ASP.NET Core Elevation Of Privilege Vulnerability

An open redirect vulnerability exists in ASP.NET Core that could lead to elevation of privilege. To exploit the vulnerability, an attacker could send a link that has a specially crafted URL, and convince the user to click the link.

When an authenticated user clicks the link, the authenticated user's browser session could be redirected to a malicious site that is designed to steal log-in session information such as cookies or authentication tokens.

The update addresses the vulnerability by correcting how ASP.NET Core handles open redirect requests.

Обновления

ПродуктСтатьяОбновление
ASP.NET Core 2.0

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 90%
0.0572
Низкий

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".

CVSS3: 8.8
github
около 3 лет назад

Open redirect in ASP.NET Core

EPSS

Процентиль: 90%
0.0572
Низкий