Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-24070

Опубликовано: 11 мар. 2025
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

A flaw was found in the SignInManager.RefreshSignInAsync method. This flaw allows an attacker with local access and low privileges to escalate privileges. The issue might lead to unauthorized access or manipulation of authentication sessions.

Отчет

.NET 6.0 for RHEL-8, RHEL-9 and RHIVOS has reached its End of Life as of November 12, 2024, and is no longer supported. No fixes will be provided for this stream. For additional information about lifecycle for .NET on Red Hat Enterprise Linux, please refer to: https://access.redhat.com/support/policy/updates/net-core.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet8.0Not affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 9dotnet6.0Out of support scope
Red Hat Enterprise Linux 9dotnet7.0Out of support scope
Red Hat Enterprise Linux 8dotnet9.0FixedRHSA-2025:266711.03.2025
Red Hat Enterprise Linux 8dotnet8.0FixedRHSA-2025:267011.03.2025
Red Hat Enterprise Linux 9dotnet9.0FixedRHSA-2025:266811.03.2025
Red Hat Enterprise Linux 9dotnet8.0FixedRHSA-2025:266911.03.2025
Red Hat Enterprise Linux 9.4 Extended Update Supportdotnet8.0FixedRHSA-2025:266611.03.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2349733dotnet: Privilege Escalation Vulnerability in .NET SignInManager.RefreshSignInAsync Method

EPSS

Процентиль: 55%
0.00319
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
ubuntu
около 1 года назад

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 7
nvd
около 1 года назад

Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 7
msrc
около 1 года назад

ASP.NET Core and Visual Studio Elevation of Privilege Vulnerability

rocky
11 месяцев назад

Important: .NET 8.0 security, bug fix, and enhancement update

rocky
11 месяцев назад

Important: .NET 9.0 security, bug fix, and enhancement update

EPSS

Процентиль: 55%
0.00319
Низкий

7.8 High

CVSS3