CVE-2018-0784

4 documents4 sources
Severity
8.8HIGH
EPSS
15.7%
top 5.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 10
Latest updateMay 13

Description

ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Elevation Of Privilege Vulnerability". This CVE is unique from CVE-2018-0808.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5microsoft_corporation/asp.net_coreASP.NET Core 1.0. 1.1, and 2.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5cxg-gwxr-pcmf: ASP2022-05-13
CVEList
CVE-2018-0784: ASP2018-01-10

📋Vendor Advisories

1
Microsoft
ASP.NET Core Elevation Of Privilege Vulnerability2018-01-09
CVE-2018-0784 (HIGH CVSS 8.8) | ASP.NET Core 1.0 | cvebase.io