Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-62902

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

A flaw was found in .NET. This vulnerability allows an unauthorized attacker to disclose sensitive information over a network. The issue arises from the inclusion of functionality from an untrusted control sphere, which can be exploited to reveal data.

Отчет

Red Hat has determined that shipped versions of .NET in Red Hat products already include the fix for this vulnerability. The .NET 8.0 (8.0.30), 9.0 (9.0.19), and 10.0 (10.0.11) runtime fix versions are included in current Red Hat packages. Furthermore, the upstream advisory identifies only Microsoft.WindowsDesktop.App.Runtime (Windows Desktop) packages as vulnerable — a component not present in Red Hat's Linux .NET builds.

Меры по смягчению последствий

No mitigation is needed. All shipped versions of .NET in Red Hat products already contain the fix for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10dotnet10.0Not affected
Red Hat Enterprise Linux 10dotnet11.0Not affected
Red Hat Enterprise Linux 10dotnet8.0Not affected
Red Hat Enterprise Linux 10dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet10.0Not affected
Red Hat Enterprise Linux 8dotnet8.0Not affected
Red Hat Enterprise Linux 8dotnet9.0Not affected
Red Hat Enterprise Linux 8dotnet/sdkNot affected
Red Hat Enterprise Linux 9dotnet10.0Not affected
Red Hat Enterprise Linux 9dotnet11.0Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-829
https://bugzilla.redhat.com/show_bug.cgi?id=2514214dotnet: .NET: Information Disclosure Vulnerability

EPSS

Процентиль: 53%
0.00778
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
24 дня назад

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
nvd
24 дня назад

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

CVSS3: 6.5
msrc
24 дня назад

.NET Information Disclosure Vulnerability

CVSS3: 6.5
github
24 дня назад

Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability

CVSS3: 6.5
fstec
24 дня назад

Уязвимость программной платформы Microsoft .NET и средства разработки программного обеспечения Microsoft Visual Studio, связанная с нарушением механизма защиты данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 53%
0.00778
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-62902