Описание
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
.NET Core 1.0 on Red Hat Enterprise Linux | rh-dotnetcore10-dotnetcore | Not affected | ||
.NET Core 1.1 on Red Hat Enterprise Linux | rh-dotnetcore11-dotnetcore | Not affected | ||
Red Hat Enterprise Linux 8 | dotnet | Not affected | ||
.NET Core on Red Hat Enterprise Linux | rh-dotnet21 | Fixed | RHSA-2019:0040 | 09.01.2019 |
.NET Core on Red Hat Enterprise Linux | rh-dotnet21-dotnet | Fixed | RHSA-2019:0040 | 09.01.2019 |
.NET Core on Red Hat Enterprise Linux | rh-dotnet22 | Fixed | RHSA-2019:0040 | 09.01.2019 |
.NET Core on Red Hat Enterprise Linux | rh-dotnet22-dotnet | Fixed | RHSA-2019:0040 | 09.01.2019 |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
An information disclosure vulnerability exists in .NET Framework and .NET Core which allows bypassing Cross-origin Resource Sharing (CORS) configurations, aka ".NET Framework Information Disclosure Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7/4.7.1/4.7.2, .NET Core 2.1, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, .NET Core 2.2, Microsoft .NET Framework 4.7.2.
Exposure of Sensitive Information in System.Net.Http
Уязвимость программных платформ .NET Core и Microsoft .NET Framework, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить доступ к защищаемой информации
5.9 Medium
CVSS3