Описание
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
A flaw was found in ASP.NET Core. An authorized attacker can exploit this authentication bypass vulnerability over a network by manipulating assumed-immutable data. This can allow the attacker to elevate their privileges within the system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/udi-rhel9 | Not affected | ||
| Red Hat Enterprise Linux 10 | dotnet8.0 | Fixed | RHSA-2026:41893 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet9.0 | Fixed | RHSA-2026:41895 | 20.07.2026 |
| Red Hat Enterprise Linux 10 | dotnet10.0 | Fixed | RHSA-2026:41897 | 20.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet8.0 | Fixed | RHSA-2026:58566 | 24.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | dotnet9.0 | Fixed | RHSA-2026:58567 | 24.08.2026 |
| Red Hat Enterprise Linux 8 | dotnet9.0 | Fixed | RHSA-2026:41899 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet10.0 | Fixed | RHSA-2026:41900 | 20.07.2026 |
| Red Hat Enterprise Linux 8 | dotnet8.0 | Fixed | RHSA-2026:41901 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | dotnet8.0 | Fixed | RHSA-2026:41894 | 20.07.2026 |
Показывать по
10
Дополнительная информация
Статус:
Important
Дефект:
CWE-472
https://bugzilla.redhat.com/show_bug.cgi?id=2500502ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass
EPSS
Процентиль: 51%
0.00736
Низкий
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 8.8
ubuntu
2 месяца назад
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
CVSS3: 8.8
nvd
2 месяца назад
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
EPSS
Процентиль: 51%
0.00736
Низкий
8.8 High
CVSS3