Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2017-8700

Опубликовано: 14 нояб. 2017
Источник: msrc
EPSS Средний

Описание

ASP.NET Core Information Disclosure Vulnerability

An information disclosure vulnerability exists in ASP.NET Core that allows bypassing Cross-origin Resource Sharing (CORS) configurations.

An attacker who successfully exploited the vulnerability could retrieve content, that is normally restricted, from a web application.

The security update addresses the vulnerability by enforcing CORS configuration to prevent its bypass.

Обновления

ПродуктСтатьяОбновление
ASP.NET Core 1.1
ASP.NET Core 1.0

Показывать по

Возможность эксплуатации

Publicly Disclosed

Yes

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

EPSS

Процентиль: 95%
0.21427
Средний

Связанные уязвимости

CVSS3: 8.7
redhat
больше 7 лет назад

ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".

CVSS3: 7.5
nvd
больше 7 лет назад

ASP.NET Core 1.0, 1.1, and 2.0 allow an attacker to bypass Cross-origin Resource Sharing (CORS) configurations and retrieve normally restricted content from a web application, aka "ASP.NET Core Information Disclosure Vulnerability".

CVSS3: 7.5
github
около 3 лет назад

Cross-origin Resource Sharing bypass in ASP.NET Core

EPSS

Процентиль: 95%
0.21427
Средний