CVE-2018-8292Sensitive Information Exposure in Microsoft NET Core

Severity
7.5HIGHNVD
EPSS
6.8%
top 8.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 10
Latest updateApr 21

Description

An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5microsoft/net_core1.0, 1.1, 2.1+2
NVDmicrosoft/asp.net_core1.0, 1.1, 2.1+2

Patches

🔴Vulnerability Details

3
OSV
.NET Core Information Disclosure2021-04-21
GHSA
.NET Core Information Disclosure2021-04-21
CVEList
CVE-2018-8292: An information disclosure vulnerability exists in2018-10-10

📋Vendor Advisories

2
Microsoft
.NET Core Information Disclosure Vulnerability2018-10-09
Red Hat
Core: information disclosure due to authentication information exposed in a redirect2018-10-09

💬Community

1
Bugzilla
CVE-2018-8292 .NET Core: information disclosure due to authentication information exposed in a redirect2018-10-04
CVE-2018-8292 — Sensitive Information Exposure | cvebase