CVE-2018-8292
published 2018-10-10CVE-2018-8292: An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
14.83%
96.3th percentile
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | asp.net_core | — | — |
| microsoft | net_core | — | — |
| microsoft | net_core | — | — |
| microsoft | net_core | — | — |
| microsoft | powershell_core | — | — |
| microsoft | system.net.http | >= 0 < 4.3.4 | 4.3.4 |
| msrc | net_core_1.0 | — | — |
| msrc | net_core_1.1 | — | — |
| msrc | net_core_2.1 | — | — |
| msrc | powershell_core_6.0 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
.NET Core Information Disclosure Vulnerability
vendor_msrc·2018-10-09·CVSS 7.5
CVE-2018-8292 [HIGH] .NET Core Information Disclosure Vulnerability
.NET Core Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect.
An attacker who successfully exploited this vulnerability could use the information to further compromise the web application.
The security update addresses the vulnerability by correcting how .NET Core handles redirects.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.
.NET Core: .NET Core
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Expl
Red Hat
Core: information disclosure due to authentication information exposed in a redirect
vendor_redhat·2018-10-09·CVSS 7.5
CVE-2018-8292 [HIGH] CWE-201 Core: information disclosure due to authentication information exposed in a redirect
Core: information disclosure due to authentication information exposed in a redirect
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
Package: rh-dotnet20-dotnet (.NET Core 2.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rh-dotnet21-dotnet (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
OSV
.NET Core Information Disclosure
osv·2021-04-21
CVE-2018-8292 [HIGH] .NET Core Information Disclosure
.NET Core Information Disclosure
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
GHSA
.NET Core Information Disclosure
ghsa·2021-04-21
CVE-2018-8292 [HIGH] CWE-200 .NET Core Information Disclosure
.NET Core Information Disclosure
An information disclosure vulnerability exists in .NET Core when authentication information is inadvertently exposed in a redirect, aka ".NET Core Information Disclosure Vulnerability." This affects .NET Core 2.1, .NET Core 1.0, .NET Core 1.1, PowerShell Core 6.0.
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105548https://access.redhat.com/errata/RHSA-2018:2902https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292http://www.securityfocus.com/bid/105548https://access.redhat.com/errata/RHSA-2018:2902https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8292
2018-10-10
Published