CVE-2021-34532
published 2021-08-12CVE-2021-34532: ASP.NET Core and Visual Studio Information Disclosure Vulnerability
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
1.12%
62.6th percentile
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | asp.net_core | 2.1 – 2.1.2 | — |
| microsoft | asp.net_core | 3.1 – 3.1.17 | — |
| microsoft | asp.net_core | 5.0 – 5.0.8 | — |
| microsoft | asp.net_core_2.1 | >= 2.0 < 2.1.29 | 2.1.29 |
| microsoft | asp.net_core_3.1 | >= 3.0 < 3.1.18 | 3.1.18 |
| microsoft | asp.net_core_5.0 | >= 5.0 < 5.0.9 | 5.0.9 |
| microsoft | microsoft_visual_studio_2019_version_16.10 | >= 16.10.0 < 16.10.5 | 16.10.5 |
| microsoft | microsoft_visual_studio_2019_version_16.4 | >= 16.0 < 16.4.25 | 16.4.25 |
| microsoft | microsoft_visual_studio_2019_version_16.7 | >= 16.0.0 < 16.7.18 | 16.7.18 |
| microsoft | microsoft_visual_studio_2019_version_16.9 | >= 15.0.0 < 16.9.10 | 16.9.10 |
| microsoft | visual_studio_2019 | — | — |
| microsoft | visual_studio_2019 | 16.0 – 16.10 | — |
| microsoft | visual_studio_2019_for_mac_version_8.10 | >= 8.1.0 < 8.10.7 | 8.10.7 |
| msrc | asp.net_core_2.1 | — | — |
| msrc | asp.net_core_3.1 | — | — |
| msrc | asp.net_core_5.0 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.10 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.4 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.7 | — | — |
| msrc | microsoft_visual_studio_2019_version_16.9 | — | — |
| msrc | visual_studio_2019_for_mac_version_8.10 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
ASP.NET Core Information Disclosure Vulnerability
ghsa·2021-08-25
CVE-2021-34532 [MEDIUM] ASP.NET Core Information Disclosure Vulnerability
ASP.NET Core Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where a JWT token is logged if it cannot be parsed.
### Patches
* If you're using .NET 5.0, you should download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0.
* If you're using .NET Core 3.1, you should download and install Runtime 3.1.18 or SDK 3.1.118 (for Vis
OSV
ASP.NET Core Information Disclosure Vulnerability
osv·2021-08-25
CVE-2021-34532 [MEDIUM] ASP.NET Core Information Disclosure Vulnerability
ASP.NET Core Information Disclosure Vulnerability
Microsoft is releasing this security advisory to provide information about a vulnerability in .NET 5.0, .NET Core 3.1 and .NET Core 2.1. This advisory also provides guidance on what developers can do to update their applications to remove this vulnerability.
An information disclosure vulnerability exists in .NET 5.0, .NET Core 3.1 and .NET Core 2.1 where a JWT token is logged if it cannot be parsed.
### Patches
* If you're using .NET 5.0, you should download and install Runtime 5.0.9 or SDK 5.0.206 (for Visual Studio 2019 v16.8) or SDK 5.0.303 (for Visual Studio 2019 V16.10) from https://dotnet.microsoft.com/download/dotnet-core/5.0.
* If you're using .NET Core 3.1, you should download and install Runtime 3.1.18 or SDK 3.1.118 (for Vis
Microsoft
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
vendor_msrc·2021-08-10·CVSS 5.5
CVE-2021-34532 [MEDIUM] ASP.NET Core and Visual Studio Information Disclosure Vulnerability
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is data inside the targeted website like IDs, tokens, nonces, and other sensitive information.
ASP.NET Core & Visual Studio: ASP.NET Core & Visual Studio
Microsoft: Microsoft
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Reference: https://dotnet.microsoft.com/download/dotnet-core/2.1
Reference: https://dotnet.microsoft.com/download/dotnet-core/3.1
Reference: https://dotnet.m
Red Hat
dotnet: ASP.NET Core JWT token logging
vendor_redhat·2021-08-10·CVSS 5.5
CVE-2021-34532 [MEDIUM] CWE-532 dotnet: ASP.NET Core JWT token logging
dotnet: ASP.NET Core JWT token logging
ASP.NET Core and Visual Studio Information Disclosure Vulnerability
Package: rh-dotnet21 (.NET Core 2.1 on Red Hat Enterprise Linux) - Not affected
Package: dotnet (Red Hat Enterprise Linux 8) - Not affected
No detection rules found.
No public exploits indexed.
2021-08-12
Published