Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-41355

Опубликовано: 12 окт. 2021
Источник: redhat
CVSS3: 5.7
EPSS Средний

Описание

.NET Core and Visual Studio Information Disclosure Vulnerability

A flaw was found in dotnet, where the System.DirectoryServices.Protocols.LdapConnection sends credentials in plaintext if the Transport Layer Security (TLS) handshake fails. This flaw allows an attacker to intercept sensitive information. The highest threat from this vulnerability is to confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 3.1 on Red Hat Enterprise Linuxrh-dotnet31-dotnetNot affected
Red Hat Enterprise Linux 8dotnet3.1Not affected
Red Hat Enterprise Linux 9dotnet3.1Not affected
.NET Core on Red Hat Enterprise Linuxrh-dotnet50-dotnetFixedRHSA-2021:381812.10.2021
Red Hat Enterprise Linux 8dotnet5.0FixedRHSA-2021:381912.10.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-319
https://bugzilla.redhat.com/show_bug.cgi?id=2011487dotnet: System.DirectoryServices.Protocols.LdapConnection sends credentials in plaintext if TLS handshake fails

EPSS

Процентиль: 97%
0.20342
Средний

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
почти 5 лет назад

.NET Core and Visual Studio Information Disclosure Vulnerability

CVSS3: 5.7
msrc
почти 5 лет назад

.NET Core and Visual Studio Information Disclosure Vulnerability

rocky
почти 5 лет назад

Important: .NET 5.0 security and bugfix update

CVSS3: 5.7
github
почти 5 лет назад

Credential Disclosure in System.DirectoryServices.Protocols

oracle-oval
почти 5 лет назад

ELSA-2021-3819: .NET 5.0 security and bugfix update (IMPORTANT)

EPSS

Процентиль: 97%
0.20342
Средний

5.7 Medium

CVSS3