Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2018-8292

Опубликовано: 09 окт. 2018
Источник: msrc
EPSS Низкий

Описание

.NET Core Information Disclosure Vulnerability

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect.

An attacker who successfully exploited this vulnerability could use the information to further compromise the web application.

The security update addresses the vulnerability by correcting how .NET Core handles redirects.

FAQ

What type of information could be disclosed by this vulnerability?

The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

Обновления

ПродуктСтатьяОбновление
.NET Core 1.0
.NET Core 1.1
PowerShell Core 6.0
.NET Core 2.1

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation More Likely

Older Software Release

Exploitation More Likely

EPSS

Процентиль: 86%
0.03179
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

CVSS3: 7.4
redhat
почти 7 лет назад

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

CVSS3: 7.5
nvd
почти 7 лет назад

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

CVSS3: 7.5
github
больше 4 лет назад

.NET Core Information Disclosure

CVSS3: 7.5
fstec
почти 7 лет назад

Уязвимость программного средства .NET Core и расширяемого средства автоматизации PowerShell Core, связанная с ошибками процедуры аутентификации, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 86%
0.03179
Низкий